SC-200 Manage a security operations environment Practice Question
Which TWO actions should you take to ensure that Microsoft Sentinel can properly ingest logs from a Linux server running rsyslog? (Choose two.)
⚠ Common exam trap
Many candidates assume syslog must be sent on the standard port 514 (TCP or UDP) or that replacing rsyslog with syslog-ng is necessary, but the Log Analytics agent specifically requires forwarding to UDP 25224 and works with rsyslog out of the box.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the Log Analytics agent (or Azure Monitor Agent) on the Linux server
The Log Analytics agent (or Azure Monitor Agent) must be installed on the Linux server to receive and forward syslog data to Microsoft Sentinel. Without the agent, Sentinel has no direct mechanism to collect logs from the server. The agent listens for syslog messages forwarded by rsyslog and then sends them to the Log Analytics workspace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install and configure syslog-ng instead of rsyslog
Why it's wrong here
Replacing rsyslog with syslog-ng is not necessary and unlikely to resolve the issue. The Microsoft Log Analytics agent for Linux explicitly supports the standard rsyslog daemon that ships with most distributions, and rsyslog can be configured to forward all required facility and severity levels to the agent. Introducing syslog-ng adds another moving part without changing the underlying requirement, which is having the Log Analytics agent installed and listening for forwarded events on UDP 25224.
- ✗
Configure rsyslog to forward logs to the agent on TCP 514
Why it's wrong here
Configuring rsyslog to forward logs on TCP 514 will fail because the Log Analytics agent does not listen on port 514. On Linux, priviledged port 514 is typically bound by the system syslog daemon itself, and the agent instead listens on UDP 25224 to receive re-forwarded syslog messages. The correct forwarding rule must target 127.0.0.1:25224 using UDP, not port 514 over TCP, so this option does not establish the required data path.
- ✓
Install the Log Analytics agent (or Azure Monitor Agent) on the Linux server
Why this is correct
The Log Analytics agent (or Azure Monitor Agent) must be installed on the Linux server before any syslog collection can occur. The agent acts as the local collector: it listens on UDP 25224 for syslog messages forwarded by the rsyslog daemon, applies filtering rules for facilities and severities, and then sends the parsed events to the Log Analytics workspace. Without the agent, there is no component to receive and ingest the syslog stream, regardless of rsyslog configuration.
- ✗
Configure Windows Event Forwarding (WEF) to collect logs from the Linux server
Why it's wrong here
Windows Event Forwarding (WEF) is a Windows-only technology that uses the Windows Event Log service and WinRM to forward Windows event logs to a collector. Linux servers do not maintain Windows Event Logs or run the required WEF components, so WEF cannot collect syslog from a Linux machine. This option misunderstands the platform boundary; Linux syslog requires the agent-based rsyslog forwarding pipeline, not WEF.
- ✓
Configure rsyslog to forward logs to the Log Analytics agent on UDP 25224
Why this is correct
Pointing rsyslog at the Log Analytics agent on UDP 25224 is the correct forwarding action. The rsyslog configuration should include a rule that sends messages to 127.0.0.1:25224 using the UDP protocol, which is the endpoint where the agent listens. Once the agent receives the syslog data, it filters it according to the defined facilities and severities before transferring it to the Log Analytics workspace, making this the required complement to installing the agent.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.