Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization uses Microsoft Sentinel as a SIEM. You need to collect security events from on-premises servers. Which connector should you use?

⚠ Common exam trap

Many candidates confuse the Log Analytics workspace (a storage container) with a data connector, or assume the Azure Security Center connector can collect raw event logs, when in fact only the Azure Monitor Agent (AMA) provides the direct, agent-based collection of security events from on-premises servers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Monitor Agent (AMA)

The Azure Monitor Agent (AMA) is the correct connector because it is the primary agent for collecting security events from on-premises Windows and Linux servers into a Log Analytics workspace, which Microsoft Sentinel uses as its data source. AMA supports data collection rules (DCRs) to filter and route specific security event IDs, replacing the legacy Log Analytics agent. This enables Sentinel to ingest Windows Security Events (e.g., Event ID 4625 for failed logons) for threat detection and incident creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure Monitor Agent (AMA)

    Why this is correct

    The Azure Monitor Agent (AMA) is the primary agent for collecting logs and performance data from virtual machines and physical servers, including those located on-premises. It replaces the legacy Log Analytics agent (MMA) and offers enhanced security, cost management, and multi-homing capabilities. AMA sends this collected data directly to a Log Analytics workspace, which serves as Sentinel's data repository for analysis and threat detection.

  • Azure Security Center connector

    Why it's wrong here

    The Azure Security Center connector, now known as the Microsoft Defender for Cloud connector, is designed to ingest security alerts, recommendations, and secure score data from Defender for Cloud into Sentinel. Its purpose is to centralize security posture management and threat protection insights for Azure resources, not to collect raw event logs from on-premises servers. Therefore, it does not facilitate the direct ingestion of on-premises system events required for comprehensive SIEM coverage.

  • Microsoft 365 Defender connector

    Why it's wrong here

    The Microsoft 365 Defender connector specifically integrates security alerts, incidents, and raw data from the various components of the Microsoft 365 Defender suite, such as Defender for Endpoint, Identity, and Office 365. This connector focuses on cloud-native security signals and threat intelligence related to user identities, endpoints, and SaaS applications. It is not designed to collect generic system event logs from on-premises infrastructure like servers or workstations.

  • Log Analytics workspace

    Why it's wrong here

    A Log Analytics workspace serves as the fundamental data repository within Azure Monitor, where all collected logs and metrics are stored, indexed, and made available for querying and analysis. While it is the ultimate destination for data ingested into Sentinel, it is not a connector or an agent itself. It provides the storage and analytics engine, but a separate mechanism, such as an agent or a data connector, is required to actually send data from a source to the workspace.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.