SC-200 Manage a security operations environment Practice Question
Which TWO are valid methods to connect a non-Azure Windows server to Microsoft Sentinel? (Choose two.)
⚠ Common exam trap
Candidates often confuse Windows Event Forwarding (WEF) as a direct data connector to Sentinel, when in fact WEF only centralizes events on a collector server, which still requires an agent to forward to Sentinel, making it an indirect method not listed as a direct connection option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the Azure Monitor Agent (AMA)
The Azure Monitor Agent (AMA) is the current, recommended agent for collecting data from non-Azure Windows servers and sending it to Microsoft Sentinel. It replaces the older Log Analytics agent and supports data collection via Data Collection Rules (DCRs), which allow granular control over which events and performance counters are ingested. Option D is correct because the Log Analytics agent (MMA) was the original method to connect Windows servers to Sentinel, and while it is being phased out in favor of AMA, it remains a valid supported method for existing deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Install the Azure Monitor Agent (AMA)
Why this is correct
The Azure Monitor Agent (AMA) is the current, unified agent for collecting telemetry from both Azure and non-Azure resources, including Windows servers outside Azure. After you install AMA and associate it with your Log Analytics workspace, you define collection rules via Data Collection Rules (DCRs) to capture security events such as 4624/4625, performance counters, and custom logs for Microsoft Sentinel. For a non-Azure Windows server, you install AMA with an onboarding script or via a management tool, and Sentinel then ingests the data from the Log Analytics workspace as its underlying telemetry source.
- ✗
Install the Azure Security Center agent
Why it's wrong here
The Azure Security Center agent is not a standalone connector for non-Azure Windows servers; it is a security monitoring extension oriented toward Azure VMs and Defender for Cloud protection plans. Installing it outside Azure does not satisfy Sentinel's ingestion path, because the required data flow is the same Windows Event Log data connector through a Log Analytics workspace using AMA or MMA. In fact, the 'Azure Security Center agent' name is legacy, and the modern equivalent is the Defender for Cloud workload protection agent, which still depends on AMA or MMA rather than being a separate agent. Therefore, this is not one of the valid methods for connecting a non-Azure Windows server.
- ✗
Configure Windows Event Forwarding (WEF) and point it to Sentinel
Why it's wrong here
Windows Event Forwarding (WEF) is a Windows protocol for forwarding event logs from source machines to a central Windows Event Collector (WEC) over HTTP/HTTPS, not directly to Microsoft Sentinel. Without an agent on the collector, the forwarded events land in a local WinRM/Event Log store, and someone must configure the Log Analytics agent or AMA on that collector with a Windows Event Logs data connector to push them into the Sentinel workspace. Pointing WEF at Sentinel's ingestion endpoint is impossible because Sentinel lacks a native WEF receiver. Thus, WEF alone is insufficient and cannot be listed as a valid connection method.
- ✓
Install the Log Analytics agent (MMA)
Why this is correct
Installing the Log Analytics agent (MMA) directly on a non-Azure Windows server enables it to collect security events and other log data from that machine. The agent then securely transmits this information to a designated Log Analytics workspace, which serves as the primary data ingestion point for Microsoft Sentinel. This mechanism specifically supports connecting servers located outside of Azure, fulfilling the scenario's requirement for a non-Azure Windows server.
- ✗
Configure the server to forward syslog to Sentinel
Why it's wrong here
Syslog is a UDP/TCP-based logging standard native to Linux/Unix and many network appliances; it is not a protocol that a Windows server natively emits, and the Microsoft Sentinel Syslog connector is designed to receive syslog from Linux or network devices through an agent installed on a Linux machine. A non-Azure Windows server would require an intermediary Linux syslog forwarder with the Log Analytics agent or AMA installed, so configuring the server itself to 'forward syslog to Sentinel' is technically invalid and is not one of the valid options. The existing Azure Monitor Agent on Windows collects Windows Event Logs directly via a DCR instead.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.