SC-200 Manage a security operations environment Practice Question
Which THREE components are required to collect syslog messages from a network appliance into Microsoft Sentinel using the Azure Monitor Agent?
⚠ Common exam trap
Many exam-takers confuse the Syslog data connector (a configuration blade in Sentinel) as a required component, when in fact it is just a UI helper; the actual collection relies on the syslog daemon, AMA, and a DCR, which are the three components explicitly tested.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A syslog daemon (e.g., rsyslog) on the log collector server to receive messages.
Syslog messages are sent over UDP (or TCP) by network appliances, and a syslog daemon like rsyslog must be running on the log collector server to listen on port 514 (or a custom port) and receive those messages. Without this daemon, the Azure Monitor Agent cannot ingest the raw syslog data, as the agent relies on the local syslog daemon to capture and forward the logs to its event pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A syslog daemon (e.g., rsyslog) on the log collector server to receive messages.
Why this is correct
The syslog daemon (typically rsyslog) is the foundational listener that binds to UDP/TCP port 514 on the log collector server and receives raw syslog messages forwarded by network appliances. Without this daemon, incoming syslog packets would have no process to capture them, so the Azure Monitor Agent would have nothing to read and no data would reach Sentinel. The daemon must be configured to accept remote input and write messages to a local log file that the agent can monitor.
- ✓
The Azure Monitor Agent installed on a log collector server.
Why this is correct
The Azure Monitor Agent (AMA) is the modern, hosted agent that runs on the same log collector server as the syslog daemon and is responsible for ingesting the local syslog logs into Azure. AMA reads the syslog files written by the daemon, parses them, and transmits the events to the Log Analytics workspace according to the assigned Data Collection Rule. Without AMA, syslog messages remain trapped on the collector server and never become accessible to Microsoft Sentinel for querying and detection.
- ✗
The Log Analytics agent (MMA) installed on the appliance.
Why it's wrong here
This is wrong because the network appliance is the source that originates syslog messages and sends them over the network; it does not host the collection agent. The legacy Log Analytics agent (MMA) was historically used on a collector VM to gather syslog, but it has been deprecated in favor of the Azure Monitor Agent. Even if MMA were installed on the appliance, it would not intercept syslog traffic destined for the collector daemon, and it is not a required or supported component for modern Sentinel syslog ingestion.
- ✗
The Syslog data connector in Microsoft Sentinel.
Why it's wrong here
The Syslog data connector in Microsoft Sentinel is an optional convenience that helps set up the ingestion pipeline by automatically creating a Data Collection Rule and enabling the collection. It does not itself receive, process, or transport syslog messages—this is entirely handled by the syslog daemon, the Azure Monitor Agent, and the DCR. Once the DCR and agent are configured, syslog data flows to Sentinel regardless of whether the connector is explicitly enabled, so it is not a mandatory component.
- ✓
A Data Collection Rule (DCR) specifying the syslog facilities and severities.
Why this is correct
A Data Collection Rule (DCR) is mandatory because it defines the exact syslog facilities (e.g., auth, kern, daemon) and severity levels (e.g., warning, critical) that the Azure Monitor Agent should collect, and it specifies the destination Log Analytics workspace and data stream. Without a DCR, AMA does not know which logs to parse or where to send them, so no syslog data is ingested. The DCR effectively acts as the filter and routing instruction set that ties the local collection stack to Microsoft Sentinel.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.