Courseiva

SC-200 Manage a security operations environment Practice Question

You are setting up Microsoft Sentinel for the first time. You need to ingest Windows security events from on-premises servers using the Azure Monitor Agent. Which data connector should you enable in Microsoft Sentinel?

⚠ Common exam trap

Many exam-takers confuse 'Syslog via AMA' with Windows event collection, but Syslog is a Linux-centric protocol (UDP/TCP 514) and cannot natively read Windows Event Log files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Security Events via AMA

The Windows Security Events via AMA data connector is specifically designed to collect Windows security events (e.g., Event ID 4625, 4688) from on-premises servers using the Azure Monitor Agent (AMA). This connector leverages the AMA's Data Collection Rules (DCRs) to filter and ingest security-relevant logs directly into Microsoft Sentinel, making it the correct choice for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Common Event Format (CEF) via AMA

    Why it's wrong here

    The Common Event Format (CEF) via AMA connector is designed for third-party security appliances—such as firewalls or security gateways—that emit logs in the CEF standard over syslog. It does not read the native Windows Event Log, so it will not collect Windows Security events like logon or process creation. For this first-time Sentinel setup, choosing CEF would require a separate forwarder for non-Microsoft devices, making it incorrect for the stated goal of collecting Windows security events.

  • ✓

    Windows Security Events via AMA

    Why this is correct

    Windows Security Events via AMA is the correct connector because it uses the Azure Monitor Agent to collect security-relevant events directly from the Windows Event Log (Security, System, Application). This connector gives you the audit trail needed for detection rules, UEBA, and incident investigation—covering events like 4624 logon successes, 4625 failures, and 4688 process creation. As AMA is the supported replacement for the legacy Log Analytics agent, this is the standard, first-party choice for Windows security telemetry in Sentinel.

  • ✗

    Syslog via AMA

    Why it's wrong here

    Syslog via AMA collects messages from Linux servers or network appliances that send RFC 3164 or RFC 5424 syslog protocol messages, typically through a local syslog daemon such as rsyslog. It does not query the Windows Event Log and therefore cannot ingest native Windows Security auditing events like account logon or privilege use. Even though some Windows systems can be configured to emit syslog, the Sentinel Syslog connector is not the intended mechanism for capturing Windows security logs.

  • ✗

    DNS via AMA

    Why it's wrong here

    The DNS via AMA connector is a specialized data connector that ingests analytic events from the DNS Server log, focusing on domain name resolution queries and responses for threat hunting in DNS-related attacks. It does not collect general Windows Security events such as user authentication, process execution, or file access, which are the core data needed for a default Windows security baseline. Therefore, for initial Sentinel setup to monitor Windows security events, this connector is not applicable, despite also using AMA.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.