Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A company is migrating its on-premises servers to Azure and needs to ensure consistent security monitoring and threat detection for both cloud and hybrid environments. They want to use Azure Security Center (now Microsoft Defender for Cloud) to achieve this. Which component of Defender for Cloud is essential for extending security monitoring to non-Azure (on-premises and other cloud) machines?

  1. AAzure Monitor Agent (AMA)
  2. BAzure DDoS Protection
  3. CAzure Network Security Groups (NSGs)
  4. DAzure Activity Logs
Show answer & explanation

Correct answer: A. Azure Monitor Agent (AMA)

The Azure Monitor Agent (AMA) collects monitoring data from the guest operating system of Azure VMs, on-premises machines, and machines in other clouds, and sends it to Log Analytics workspaces, enabling Defender for Cloud to monitor these hybrid environments.

Why the other options are wrong

  • B. Azure DDoS Protection safeguards Azure resources from DDoS attacks, not for extending security monitoring to hybrid machines.
  • C. NSGs filter network traffic within Azure virtual networks, they don't extend monitoring to hybrid environments.
  • D. Azure Activity Logs record control-plane events in Azure, not guest OS data from hybrid machines.

Azure Monitor Agent (AMA)

The Azure Monitor Agent (AMA) is the primary agent for collecting monitoring data from Azure virtual machines, Azure Arc-enabled servers, and other cloud machines. It replaces legacy agents and offers enhanced capabilities for data collection and management.

  • Collects data from guest OS of VMs and hybrid machines.
  • Sends data to Log Analytics workspaces.
  • Supports custom data collection rules.
  • Essential for Microsoft Defender for Cloud's hybrid capabilities.

Memory trick: An Agent bridges the gap between cloud and home.

More Manage security operations questions