SC-200 Manage a security operations environment Practice Question
You are setting up Microsoft Sentinel for the first time. You need to ingest Windows security events from on-premises servers using the Azure Monitor Agent. Which data connector should you enable in Microsoft Sentinel?
⚠ Common exam trap
Many exam-takers confuse 'Syslog via AMA' with Windows event collection, but Syslog is a Linux-centric protocol (UDP/TCP 514) and cannot natively read Windows Event Log files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security Events via AMA
The Windows Security Events via AMA data connector is specifically designed to collect Windows security events (e.g., Event ID 4625, 4688) from on-premises servers using the Azure Monitor Agent (AMA). This connector leverages the AMA's Data Collection Rules (DCRs) to filter and ingest security-relevant logs directly into Microsoft Sentinel, making it the correct choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Common Event Format (CEF) via AMA
Why it's wrong here
The Common Event Format (CEF) via AMA connector is designed for third-party security appliances—such as firewalls or security gateways—that emit logs in the CEF standard over syslog. It does not read the native Windows Event Log, so it will not collect Windows Security events like logon or process creation. For this first-time Sentinel setup, choosing CEF would require a separate forwarder for non-Microsoft devices, making it incorrect for the stated goal of collecting Windows security events.
- ✓
Windows Security Events via AMA
Why this is correct
Windows Security Events via AMA is the correct connector because it uses the Azure Monitor Agent to collect security-relevant events directly from the Windows Event Log (Security, System, Application). This connector gives you the audit trail needed for detection rules, UEBA, and incident investigation—covering events like 4624 logon successes, 4625 failures, and 4688 process creation. As AMA is the supported replacement for the legacy Log Analytics agent, this is the standard, first-party choice for Windows security telemetry in Sentinel.
- ✗
Syslog via AMA
Why it's wrong here
Syslog via AMA collects messages from Linux servers or network appliances that send RFC 3164 or RFC 5424 syslog protocol messages, typically through a local syslog daemon such as rsyslog. It does not query the Windows Event Log and therefore cannot ingest native Windows Security auditing events like account logon or privilege use. Even though some Windows systems can be configured to emit syslog, the Sentinel Syslog connector is not the intended mechanism for capturing Windows security logs.
- ✗
DNS via AMA
Why it's wrong here
The DNS via AMA connector is a specialized data connector that ingests analytic events from the DNS Server log, focusing on domain name resolution queries and responses for threat hunting in DNS-related attacks. It does not collect general Windows Security events such as user authentication, process execution, or file access, which are the core data needed for a default Windows security baseline. Therefore, for initial Sentinel setup to monitor Windows security events, this connector is not applicable, despite also using AMA.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.