Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard

An organization is deploying Microsoft Sentinel and wants to ensure that all security events from their on-premises domain controllers are ingested. These domain controllers run Windows Server 2019. Which agent and data connector combination is required to collect these security events?

  1. AAzure Monitor Agent (AMA) with Syslog connector
  2. BLog Analytics agent (MMA) with Windows Security Events via Legacy connector
  3. CAzure Monitor Agent (AMA) with Windows Security Events via AMA connector
  4. DMicrosoft Defender for Endpoint agent with Microsoft 365 Defender connector
Show answer & explanation

Correct answer: C. Azure Monitor Agent (AMA) with Windows Security Events via AMA connector

For Windows Server 2019, the recommended agent for collecting security events is the Azure Monitor Agent (AMA). The corresponding data connector in Sentinel is 'Windows Security Events via AMA', which specifically leverages AMA to collect these logs.

Why the other options are wrong

  • A. Syslog connector is used for Linux-based systems or network devices, not Windows Security Events.
  • B. The Log Analytics agent (MMA) is considered a legacy agent and while it can collect Windows Security Events, AMA is the current recommended approach for Windows Server 2019 and newer.
  • D. Microsoft Defender for Endpoint agent collects endpoint detection and response data, not raw Windows Security Events for general SIEM ingestion, and the connector is for Defender for Endpoint data, not generic Windows events.

Azure Monitor Agent (AMA) for Sentinel

The unified agent for Azure Monitor that collects telemetry from Azure and non-Azure machines and sends it to Log Analytics workspaces, including for Microsoft Sentinel.

  • Replaces the legacy Log Analytics agent (MMA).
  • Uses Data Collection Rules (DCRs) for granular control over collected data.
  • Required for modern Windows Security Events ingestion into Sentinel.

Memory trick: Think of AMA as the 'new postman' for your on-premise logs, delivering them to the cloud 'mailroom'.

More Mitigate threats using Microsoft Sentinel questions