Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Cloud to monitor hybrid workloads. You need to ensure that security alerts from on-premises servers are sent to Microsoft Sentinel. What should you configure?

⚠ Common exam trap

The trap here is that candidates may mistakenly think a VPN or third-party connector is required for on-premises data ingestion, overlooking Azure Arc's ability to bridge on-premises servers into Azure management plane and enable agent-based log collection directly to Sentinel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connect the on-premises servers to Azure Arc and deploy the Log Analytics agent.

Azure Arc enables on-premises servers to be managed as Azure resources, allowing the Log Analytics agent to be deployed and configured to forward security alerts to a Log Analytics workspace integrated with Microsoft Sentinel. This is the standard method for ingesting security events from hybrid workloads into Sentinel without requiring third-party connectors or complex network configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install a third-party SIEM connector on the servers and forward logs to Sentinel.

    Why it's wrong here

    Installing a third-party SIEM connector such as CEF or Syslog on each on-premises server is not the supported Microsoft path for bringing host logs into Microsoft Sentinel. These connectors require an existing logging forwarder and do not take advantage of Azure Arc's identity or agent management capabilities. Microsoft's recommended approach is to first connect the servers to Azure Arc, then use the Log Analytics agent or Azure Monitor Agent, which Sentinel can ingest natively.

  • ✗

    Deploy Azure Policy on the servers to audit security settings.

    Why it's wrong here

    Deploying Azure Policy to audit security settings checks whether servers meet compliance criteria, but it does not forward security events or alerts to Microsoft Sentinel. Policy's 'audit' effect only reports compliance status; it cannot transform server event logs into Sentinel detections. Also, for on-premises machines, Azure Policy can only be applied after the servers are onboarded to Azure Arc, making it an incomplete solution by itself.

  • ✓

    Connect the on-premises servers to Azure Arc and deploy the Log Analytics agent.

    Why this is correct

    Connecting the on-premises servers to Azure Arc creates an Azure resource that supports a consistent management plane and enables you to install the Log Analytics agent (or Azure Monitor Agent) through Azure. The agent collects Windows/Linux security events and sends them to a Log Analytics workspace, which Microsoft Sentinel uses as its data source. This is the native, recommended architecture for migrating on-premises log collection to Sentinel.

  • ✗

    Configure a site-to-site VPN to Azure and enable network logging.

    Why it's wrong here

    Configuring a site-to-site VPN to Azure provides network-level connectivity between your on-premises environment and Azure, but it does not install any log-collection software or create data connectors to Microsoft Sentinel. Without an agent on the servers, no security logs are forwarded, and enabling network logging alone cannot make Sentinel ingest host-based events. A VPN is useful for connectivity, not for log ingestion.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender for Cloud to monitor hybrid workloads. You need to ensure that security alerts from on-premises servers running Windows Server 2022 are forwarded to Microsoft Sentinel. The servers are not yet onboarded to Azure Arc. What should you do first?

hard
  • A.Install the Azure Monitor Agent on the servers.
  • B.Deploy Azure Policy to enable Defender for Cloud on the servers.
  • ✓ C.Onboard the servers to Azure Arc and enable Defender for Cloud.
  • D.Install Microsoft Defender for Endpoint on the servers.

Why C: On-premises servers must first be onboarded to Azure Arc to establish a management identity and connectivity with Azure. Without Azure Arc, Defender for Cloud cannot apply its security policies or forward alerts to Microsoft Sentinel. Enabling Defender for Cloud on the servers after Arc onboarding allows security alerts to be collected and forwarded to Sentinel.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.