Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard
A security engineer is tasked with investigating a series of suspicious activities reported on several Azure virtual machines. The incidents indicate potential unauthorized access and privilege escalation. To effectively analyze the sequence of events and identify the root cause, the engineer needs to collect detailed system performance, process creation, and network connection data from these VMs. Which Azure Monitor agent should be deployed to these virtual machines to capture this comprehensive set of security-relevant data?
- ALog Analytics agent (MMA)
- BAzure Diagnostic Extension (ADE)
- CAzure Monitor Agent (AMA)
- DDependency agent
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Monitor Agent (AMA)
The Azure Monitor Agent (AMA) is the new unified agent designed to collect a wide range of monitoring data, including detailed security events, performance counters, process creation, and network connection data, from Azure VMs, Azure Arc-enabled servers, and on-premises machines. It offers more granular control and a broader scope of data collection compared to its predecessors.
Why the other options are wrong
- A. The Log Analytics agent (MMA) is the legacy agent. While it collected some of this data, AMA is the recommended and more comprehensive solution for detailed security monitoring, offering more granular control and efficiency.
- B. The Azure Diagnostic Extension (ADE) primarily collects guest OS performance counters, diagnostics, and logs for troubleshooting and application monitoring, but it is not optimized for comprehensive security event collection like AMA.
- D. The Dependency agent collects data about processes running on the VM and their network dependencies, primarily for application mapping and Service Map, not for comprehensive security event collection.
Azure Monitor Agent (AMA)
A unified agent for Azure Monitor that collects a wide range of monitoring data from virtual machines and servers, offering enhanced capabilities and granular control.
- Replaces Log Analytics agent (MMA) and Azure Diagnostic Extension (ADE).
- Supports data collection from Azure VMs, Azure Arc-enabled servers, and on-premises servers.
- Uses Data Collection Rules (DCRs) for granular control over collected data.
Memory trick: Agents are like 'collectors' for your VM's 'story'.