SC-200 - Manage a Security Operations Environment (41% of the exam) - Section 1.5

Select and configure Microsoft Sentinel data connectors for Windows security events, Syslog, and CEF.

Select the appropriate Microsoft Sentinel data connector for Windows Security Events via AMA, Syslog via AMA, or Common Event Format (CEF) via AMA, and configure data collection rules (DCR) to filter which event fields are forwarded. Recognise when Windows Event Forwarding (WEF) is the right collection path and how it differs from direct AMA-based ingestion.

data connector selectionWindows Security Events via AMAdata collection rules (DCR)Windows Event Forwarding (WEF)Syslog via AMACommon Event Format (CEF) via AMA

Practice question for this objective

Free sampleManage a Security Operations Environmentmedium

Your organisation is onboarding a fleet of Windows Server 2022 domain controllers into Microsoft Sentinel. Security operations need Windows security event logs ingested using the connector that Microsoft positions as current and that lets you choose which event set to collect through a data collection rule. The legacy Microsoft Monitoring Agent is being retired in your tenant. Which Microsoft Sentinel data connector should you deploy to meet this requirement?

  • ASecurity Events via Legacy Agent, configured on each domain controller so that the Microsoft Monitoring Agent forwards the selected Windows security event tiers into the Microsoft Sentinel workspace.
  • BWindows Forwarded Events, configured so that a Windows Event Collector subscription gathers security events from the domain controllers before the workspace ingests the forwarded channel.
  • CSyslog via AMA, deployed with the Azure Monitor Agent so that a data collection rule forwards the Windows security facility messages into the Microsoft Sentinel workspace for analysis.
  • DWindows Security Events via AMA, deployed with the Azure Monitor Agent so that a data collection rule defines which security event set is forwarded to the Microsoft Sentinel workspace. Correct
Choose Windows Security Events via AMA with a data collection rule as the current connector for ingesting Windows security logs into Microsoft Sentinel. The Windows Security Events via AMA connector replaces the legacy Microsoft Monitoring Agent path. It installs the Azure Monitor Agent and binds a data collection rule that lets you pick the All Security Events, Common, or Minimal event set, giving granular control over which Windows security events reach the workspace while following the supported, non-deprecated collection method.

Why A is wrong: Security Events via Legacy Agent relies on the Microsoft Monitoring Agent, which Microsoft is retiring, so although it does collect Windows security events it is the deprecated path and does not align with the requirement to use the current connector.

Why B is wrong: Windows Forwarded Events ingests events already consolidated through Windows Event Forwarding into a collector, which suits source-initiated subscription designs but is not the direct per-server security event connector the scenario describes.

Why C is wrong: Syslog via AMA collects Syslog-formatted messages from Linux and network devices, not the Windows Event Log, so it cannot ingest Windows security events even though it also relies on the Azure Monitor Agent and a data collection rule.

Why D is correct: Windows Security Events via AMA uses the Azure Monitor Agent and a data collection rule to select common, minimal, or all events, which is exactly the current Microsoft-recommended path for ingesting Windows security logs into the workspace.

See more SC-200 practice questions, answers explained.

Exam traps in Manage a Security Operations Environment

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • Security Events via Legacy Agent, because it ingests Windows security events through the Microsoft Monitoring Agent that the team already understands

    Why it is wrong: This connector relies on the Log Analytics or Microsoft Monitoring Agent, which is the retired component the requirement says to move away from, so it does not fit the current-agent constraint.

  • Common Event Format (CEF) via AMA, which uses the Azure Monitor Agent to parse vendor key-value records into the CommonSecurityLog table for both sources

    Why it is wrong: CEF via AMA parses Common Event Format appliance records into CommonSecurityLog, but neither Windows security events nor native Linux Syslog arrive as CEF, so it fits neither stated source.

  • A diagnostic setting on each Windows server that routes its security log to the workspace at the Common verbosity level

    Why it is wrong: Diagnostic settings stream Azure resource platform logs to a workspace; they do not configure the Azure Monitor Agent or offer a Common Windows security event tier, so they cannot scope this collection.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.