Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO are valid methods to ingest logs into Microsoft Sentinel from a non-Azure virtual machine? (Select TWO.)

⚠ Common exam trap

Many candidates confuse the deprecated OMS agent with the still-supported MMA legacy agent, or assume AMA can be installed on non-Azure VMs without Azure Arc, when Arc is mandatory for management plane integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Monitor Agent (AMA) with Azure Arc

Azure Arc bridges non-Azure VMs into Azure's management plane, allowing the Azure Monitor Agent (AMA) to be installed and managed as if the VM were native Azure. This enables log ingestion into Microsoft Sentinel without requiring direct Azure connectivity or a VPN, using the same AMA data collection rules (DCRs) as Azure VMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Monitor Agent (AMA) with Azure Arc

    Why this is correct

    Azure Monitor Agent (AMA) with Azure Arc is the current, recommended ingestion path for non-Azure virtual machines. AMA itself is a unified agent that collects telemetry from VMs, but for machines outside Azure, the agent must be deployed and configured through Azure Arc's management plane. Arc enables you to install AMA, assign Data Collection Rules (DCRs), and route the data into a Log Analytics workspace, which Microsoft Sentinel then ingests. Without Arc, AMA cannot be centrally managed on hybrid machines, so this pairing is a fully valid method for bringing logs into Sentinel.

  • ✓

    Log Analytics agent (MMA) – legacy

    Why this is correct

    The Log Analytics agent (MMA) provides a valid method for ingesting logs from non-Azure virtual machines as it can be directly installed on Windows and Linux operating systems, regardless of their hosting environment. This agent collects specified logs and performance data from the machine, then securely transmits it to a Log Analytics workspace. Microsoft Sentinel then ingests this data from the connected workspace, making it an effective solution for machines outside the Azure platform, despite being a legacy agent now superseded by the Azure Monitor Agent.

  • ✗

    Microsoft Sentinel agent (standalone)

    Why it's wrong here

    There is no such product as a standalone Microsoft Sentinel agent. Sentinel is not a collection agent; it ingests security data from a Log Analytics workspace, which is populated by agents such as the Azure Monitor Agent (AMA) or the legacy Log Analytics agent (MMA). Any perceived 'Sentinel agent' is actually a Log Analytics agent (or AMA) configured with security-related data collection rules. Choosing this option confuses the SIEM platform with the underlying telemetry pipeline, so it is not a valid method of log ingestion.

  • ✗

    Azure Monitor Agent (AMA) without Azure Arc

    Why it's wrong here

    AMA on a non-Azure virtual machine without Azure Arc is not a valid deployment because Arc acts as the required control plane for deploying, configuring, and updating the agent on hybrid machines. Without Arc, there is no authenticated, scalable mechanism to assign Data Collection Rules or to manage the agent's lifecycle from Azure. While AMA can run on-premises, it must be connected through Arc to be recognized and managed by Azure. Thus, selecting AMA without Arc for non-Azure VMs ignores a hard prerequisite.

  • ✗

    Log Analytics agent (OMS) – deprecated

    Why it's wrong here

    The Log Analytics agent (OMS) is the original operational management agent, now deprecated and fully replaced by the Log Analytics agent (MMA) and then by AMA. Though historically you could install it on Windows/Linux VMs and forward logs to a Log Analytics workspace, Microsoft has announced deprecation and it should not be used for new deployments. Relying on OMS not only introduces compatibility and security risks but also reflects outdated architecture; therefore it is not a valid modern method for ingesting logs into Sentinel.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.