SC-200 Manage a security operations environment Practice Question
Your company uses Microsoft Sentinel and has a workspace in the East US region. You need to ingest logs from a non-Azure Windows server located in a branch office in Europe. You have limited bandwidth and need to ensure that log ingestion does not impact network performance. What should you use?
⚠ Common exam trap
Many exam-takers assume MMA is still the default for on-premises servers, but Microsoft has deprecated MMA in favor of AMA, and AMA’s DCR-based filtering and compression directly address bandwidth constraints, which MMA cannot do natively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the Azure Monitor Agent on the server and create a data collection rule to filter and compress logs before sending.
The Azure Monitor Agent (AMA) supports data collection rules (DCRs) that can filter logs at the source and compress data before transmission, reducing bandwidth usage. This is critical for the limited bandwidth scenario, and AMA is the modern replacement for the Log Analytics agent, designed for efficient log ingestion across regions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Defender for Endpoint to collect logs from the server and forward them to Sentinel.
Why it's wrong here
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution that produces its own security alerts and device telemetry, but it is not designed to act as a general-purpose log forwarding agent. It cannot collect arbitrary operating system or application logs from an on-premises server and stream them to Sentinel; its connector only imports Defender-specific events. Therefore, while it may be useful for security insights, it does not address the requirement to forward server logs to the Sentinel workspace.
- ✗
Install the Log Analytics agent (MMA) on the server and configure it to send logs directly to the workspace.
Why it's wrong here
The Log Analytics agent (MMA) is the legacy agent that sends data directly to a Log Analytics workspace, but it is on a deprecation path with retirement announced for August 2024. It lacks the data collection rule (DCR) mechanism that enables source-side filtering and transformation, so it would send all configured logs without the ability to selectively discard irrelevant events or compress payloads as efficiently. The Azure Monitor Agent is the recommended replacement and provides better bandwidth optimization, making MMA a poor choice for a new deployment.
- ✓
Install the Azure Monitor Agent on the server and create a data collection rule to filter and compress logs before sending.
Why this is correct
The Azure Monitor Agent (AMA) is the current, cross-platform agent that supports configurable data collection rules (DCRs) for filtering, transforming, and enriching logs before they leave the server. DCR transformations, written in KQL, can discard unnecessary events, and the AMA uses an optimized protocol with built-in compression to minimize bandwidth usage. This approach directly meets the requirement to reduce the volume of data sent to Sentinel while ensuring only relevant logs are ingested.
- ✗
Configure the server to send logs to an Azure Event Hub, then stream to Sentinel.
Why it's wrong here
Routing server logs through an Azure Event Hub and then into Sentinel adds unnecessary architectural complexity and can introduce additional egress and ingress costs. Event Hub is a streaming platform, not a filtering or compression service, so the raw logs would still be transmitted in full over the network, and you would need to build an additional processing layer to reduce data volume. This approach not only fails to minimize bandwidth but also increases latency and operational overhead compared to using an agent with DCR-based filtering.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.