SC-200 Manage a security operations environment Practice Question
Which TWO are valid methods to ingest logs into Microsoft Sentinel from a non-Azure virtual machine? (Select TWO.)
⚠ Common exam trap
Many candidates confuse the deprecated OMS agent with the still-supported MMA legacy agent, or assume AMA can be installed on non-Azure VMs without Azure Arc, when Arc is mandatory for management plane integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Monitor Agent (AMA) with Azure Arc
Azure Arc bridges non-Azure VMs into Azure's management plane, allowing the Azure Monitor Agent (AMA) to be installed and managed as if the VM were native Azure. This enables log ingestion into Microsoft Sentinel without requiring direct Azure connectivity or a VPN, using the same AMA data collection rules (DCRs) as Azure VMs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Monitor Agent (AMA) with Azure Arc
Why this is correct
Azure Monitor Agent (AMA) with Azure Arc is the current, recommended ingestion path for non-Azure virtual machines. AMA itself is a unified agent that collects telemetry from VMs, but for machines outside Azure, the agent must be deployed and configured through Azure Arc's management plane. Arc enables you to install AMA, assign Data Collection Rules (DCRs), and route the data into a Log Analytics workspace, which Microsoft Sentinel then ingests. Without Arc, AMA cannot be centrally managed on hybrid machines, so this pairing is a fully valid method for bringing logs into Sentinel.
- ✓
Log Analytics agent (MMA) – legacy
Why this is correct
The Log Analytics agent (MMA) provides a valid method for ingesting logs from non-Azure virtual machines as it can be directly installed on Windows and Linux operating systems, regardless of their hosting environment. This agent collects specified logs and performance data from the machine, then securely transmits it to a Log Analytics workspace. Microsoft Sentinel then ingests this data from the connected workspace, making it an effective solution for machines outside the Azure platform, despite being a legacy agent now superseded by the Azure Monitor Agent.
- ✗
Microsoft Sentinel agent (standalone)
Why it's wrong here
There is no such product as a standalone Microsoft Sentinel agent. Sentinel is not a collection agent; it ingests security data from a Log Analytics workspace, which is populated by agents such as the Azure Monitor Agent (AMA) or the legacy Log Analytics agent (MMA). Any perceived 'Sentinel agent' is actually a Log Analytics agent (or AMA) configured with security-related data collection rules. Choosing this option confuses the SIEM platform with the underlying telemetry pipeline, so it is not a valid method of log ingestion.
- ✗
Azure Monitor Agent (AMA) without Azure Arc
Why it's wrong here
AMA on a non-Azure virtual machine without Azure Arc is not a valid deployment because Arc acts as the required control plane for deploying, configuring, and updating the agent on hybrid machines. Without Arc, there is no authenticated, scalable mechanism to assign Data Collection Rules or to manage the agent's lifecycle from Azure. While AMA can run on-premises, it must be connected through Arc to be recognized and managed by Azure. Thus, selecting AMA without Arc for non-Azure VMs ignores a hard prerequisite.
- ✗
Log Analytics agent (OMS) – deprecated
Why it's wrong here
The Log Analytics agent (OMS) is the original operational management agent, now deprecated and fully replaced by the Log Analytics agent (MMA) and then by AMA. Though historically you could install it on Windows/Linux VMs and forward logs to a Log Analytics workspace, Microsoft has announced deprecation and it should not be used for new deployments. Relying on OMS not only introduces compatibility and security risks but also reflects outdated architecture; therefore it is not a valid modern method for ingesting logs into Sentinel.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.