Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization is planning to deploy Microsoft Sentinel. You need to ensure that security events from on-premises servers are sent to Sentinel. Which connector should you use?

⚠ Common exam trap

Candidates often confuse the deprecated Log Analytics agent (MMA) with the current Azure Monitor Agent (AMA), or mistakenly believe that Azure Arc alone can forward security events, when in fact it requires an additional agent like AMA for log collection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install the Azure Monitor Agent (AMA) on the servers and configure a Data Collection Rule (DCR) to send events to Sentinel.

The Azure Monitor Agent (AMA) is the current recommended agent for collecting security events from on-premises servers and forwarding them to Microsoft Sentinel. By installing AMA and configuring a Data Collection Rule (DCR), you can specify which security events (e.g., Windows Security Event logs) to collect and send directly to the Sentinel workspace, ensuring efficient and modern data ingestion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install the Log Analytics agent (MMA) on the servers and connect to Sentinel workspace.

    Why it's wrong here

    The legacy Log Analytics agent (MMA) is being retired by Microsoft, with deprecation set for August 2024, and it is no longer the recommended agent for Sentinel data collection. Although MMA could previously send Windows/Linux security events to a Log Analytics workspace, it lacks the modern Data Collection Rule (DCR) support and scalability that the Azure Monitor Agent (AMA) provides. Choosing MMA today would create an immediate migration burden and is not a forward-looking deployment.

  • ✗

    Use the Microsoft Defender for Cloud (MDC) connector to stream security events.

    Why it's wrong here

    The Microsoft Defender for Cloud (MDC) connector in Microsoft Sentinel ingests security alerts, findings, and recommendations from Defender plans, not raw event logs from a server's OS. It does not stream Windows Security IDs, Sysmon events, or Linux syslog messages into the Sentinel workspace. You still need an agent such as the Azure Monitor Agent to collect and forward those underlying events, so this connector alone cannot satisfy a requirement to ingest security events.

  • ✗

    Enable Azure Arc on the servers and use the Arc agent to forward events.

    Why it's wrong here

    Enabling Azure Arc on the servers installs the Connected Machine agent and brings the resources under Azure management, but the Arc agent itself does not collect or forward log data to Sentinel. Azure Arc merely provides a platform to deploy extensions, including the Azure Monitor Agent, to Arc-enabled machines. Using Arc alone without installing AMA and configuring a Data Collection Rule would result in no security event data reaching the Sentinel workspace.

  • ✓

    Install the Azure Monitor Agent (AMA) on the servers and configure a Data Collection Rule (DCR) to send events to Sentinel.

    Why this is correct

    The correct approach is to install the Azure Monitor Agent (AMA) on each server, because it is the current, fully supported agent for sending logs to Azure Monitor and Microsoft Sentinel. You then define a Data Collection Rule (DCR) that specifies which security event logs — such as the Windows Security log, Sysmon, or Linux syslog — are collected and routed to the Sentinel workspace. The DCR can also apply filtering to reduce noise and control which event IDs are ingested, giving you precise and scalable collection.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.