SC-200 Manage a security operations environment Practice Question
You are configuring Microsoft Sentinel to ingest syslog data from a network appliance. After configuring the data connector, you notice that no data is appearing in the CommonSecurityLog table. The syslog server is sending data to the Azure Monitor Agent (AMA) on the log collector. What should you verify first?
⚠ Common exam trap
It's easy for candidates to assume the data connector automatically creates the necessary Data Collection Rule, when in fact the DCR must be manually configured or verified after connector setup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that a Data Collection Rule is defined to collect the syslog facilities.
The Azure Monitor Agent (AMA) requires a Data Collection Rule (DCR) to specify which syslog facilities and severity levels to collect. Without a DCR, the AMA will not forward syslog data to the CommonSecurityLog table, even if the syslog server is sending data to the collector. This is the most common missing configuration step after setting up the data connector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the Heartbeat table for the log collector.
Why it's wrong here
The Heartbeat table records periodic status messages from the Azure Monitor Agent (AMA), indicating only that the agent is installed and running on the VM. It does not contain syslog messages, nor does it reveal whether a Data Collection Rule (DCR) is configured to forward specific syslog facilities and severities. A healthy heartbeat can exist even when the DCR is missing or misconfigured, so checking this table cannot confirm syslog collection.
- ✓
Verify that a Data Collection Rule is defined to collect the syslog facilities.
Why this is correct
In Microsoft Sentinel with the Azure Monitor Agent, syslog ingestion is driven entirely by a Data Collection Rule (DCR) that explicitly lists which facilities (e.g., auth, cron, daemon) and severity levels to collect. Without such a DCR, the agent runs but the local syslog daemon has no instructions to forward any events to the Log Analytics workspace. You must verify that the DCR exists, is associated with the target VM, and includes the required facilities; simply enabling the Sentinel data connector will not create the rule automatically.
- ✗
Ensure the syslog appliance can reach the collector on UDP port 514.
Why it's wrong here
While UDP 514 reachability is necessary for the syslog appliance to deliver messages to the collector, it is rarely the root cause of missing syslog data in Sentinel. The Azure Monitor Agent uses a local syslog daemon (typically rsyslog) that listens on that port, but the daemon only forwards events that match a configured DCR. Connectivity can succeed while the DCR is absent, causing incoming events to be discarded locally, so verifying the network path is insufficient to diagnose the collection failure.
- ✗
Check the data connector health status in Sentinel.
Why it's wrong here
The data connector health status in Sentinel reflects the connector's configuration and agent connection, not the actual flow of syslog data into the workspace. A connector can display 'Connected' even when the associated DCR is missing, the facility list is incomplete, or the agent is not forwarding events. Health status is an aggregate indicator and does not expose the underlying collection rules or whether specific syslog messages are arriving in the Log Analytics workspace.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.