SC-200 Practice Question 3671

Exam: SC-200
Domain: Manage a security operations environment
Difficulty: medium
An engineer needs to onboard on-premises Windows and Linux physical servers into Microsoft Sentinel to collect Syslog and Security Events. What agent architecture is currently recommended and standard for Microsoft Sentinel ingestion?

Answer Options

A
Azure Monitor Agent (AMA) with Data Collection Rules
B
Legacy Log Analytics Agent (MMA)
C
System Center Operations Manager (SCOM) agent
D
Direct SNMP polling without agents

Correct Answer

A: Azure Monitor Agent (AMA) with Data Collection Rules

Explanation

The Azure Monitor Agent (AMA), configured with Data Collection Rules (DCRs), is the current unified agent for streaming Windows event logs, Syslog, and telemetry to Log Analytics and Sentinel.