SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel in a hybrid environment with on-premises servers and Azure VMs. You need to ensure that all Windows servers forward their security events to Sentinel. The security team wants to use Windows Security Events via AMA connector. Windows servers are not domain-joined and are managed by a third-party RMM tool. What is the most efficient way to deploy the AMA agent?
⚠ Common exam trap
Many exam-takers assume GPO or Intune are universal deployment tools, but the question's key constraint—'not domain-joined'—disqualifies GPO, and Intune requires Microsoft Entra ID join or enrollment, which is not stated; Azure Arc is the correct answer because it specifically enables management of non-Azure, non-domain-joined servers via Azure policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Onboard the servers to Azure Arc and deploy the AMA agent via policy or script.
Azure Arc provides a control plane for non-Azure and on-premises servers, enabling them to be managed like Azure resources. Once onboarded to Azure Arc, you can deploy the Azure Monitor Agent (AMA) via Azure Policy or custom scripts, which is the most efficient method for non-domain-joined servers managed by a third-party RMM tool, as it avoids manual intervention and leverages Azure's centralized management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Group Policy Objects (GPO) to push the agent installation.
Why it's wrong here
Group Policy Objects require the target computers to be members of an Active Directory domain where the policy can be fetched and applied. The servers in this scenario are not domain-joined; they live in a hybrid environment managed by a third-party RMM, so they cannot authenticate to a domain controller to receive Group Policy updates. Additionally, the Azure Monitor Agent does not have a specific GPO administrative template for silent installation, making GPO a technically unsupported method for pushing this agent.
- ✓
Onboard the servers to Azure Arc and deploy the AMA agent via policy or script.
Why this is correct
Onboarding the servers to Azure Arc registers each physical or virtual machine as a first-class Azure resource, giving it an identity and the ability to be managed via Azure Policy. Once the AzureConnectedMachine agent is installed, you can use the built-in Azure Policy definition 'Configure Windows machines to run Azure Monitor Agent' to automatically deploy the AMA at scale, or invoke a script that uses the Azure portal-created install command. Because Arc works regardless of domain membership, this is the correct and recommended path for non-domain-joined servers in a hybrid scenario.
- ✗
Use Microsoft Intune to deploy the AMA agent to all servers.
Why it's wrong here
Microsoft Intune is a cloud-based endpoint management service primarily designed for mobile devices and Windows client endpoints; for servers, it only supports Azure VMs or on-premises Windows servers that are co-managed with Microsoft Configuration Manager and require either Microsoft Entra ID or hybrid AD join. The servers here are non-domain-joined and managed by a third-party RMM, so they are not enrolled in Intune and are outside its management boundary, making Intune an impractical channel for deploying the Azure Monitor Agent.
- ✗
Manually install the agent on each server using the setup wizard.
Why it's wrong here
Performing a manual installation with the setup wizard on every server requires local administrative credentials on each machine and a physical or RDP session to the console, which is time-consuming and error-prone across many servers. It also provides no built-in method to verify which servers have been successfully agent-enabled or to track missed installations. For a hybrid fleet of non-domain-joined servers, automated deployment via Azure Arc and policy or script is the scalable and auditable alternative.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.