Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium

A security administrator needs to monitor the security posture of an on-premises server fleet alongside their Azure resources within Microsoft Defender for Cloud. The on-premises servers run Windows Server 2019. Which component or agent must be deployed on these on-premises servers to integrate them with Defender for Cloud for security recommendations and threat detection?

  1. AAzure Monitor Agent (AMA) with Azure Arc
  2. BAzure IoT Edge runtime
  3. CAzure Site Recovery Agent
  4. DAzure Network Watcher Agent
Show answer & explanation

Correct answer: A. Azure Monitor Agent (AMA) with Azure Arc

To onboard on-premises servers to Microsoft Defender for Cloud, they first need to be connected to Azure via Azure Arc, and then the Azure Monitor Agent (AMA) is deployed to collect security-related data.

Why the other options are wrong

  • B. Azure IoT Edge runtime is for Internet of Things (IoT) devices, not for general-purpose servers.
  • C. Azure Site Recovery Agent is for disaster recovery, not for security posture management.
  • D. Azure Network Watcher Agent is for network performance monitoring and diagnostics, not for general security posture management in Defender for Cloud.

Azure Arc and Azure Monitor Agent (AMA)

Azure Arc extends Azure management and services to on-premises and multi-cloud environments, while the Azure Monitor Agent (AMA) is the primary agent used to collect monitoring and security data from these connected resources for services like Microsoft Defender for Cloud.

  • Azure Arc enables hybrid cloud management.
  • AMA collects security events, performance data, and logs.
  • Required for onboarding non-Azure servers to Defender for Cloud.
  • Replaces the legacy Log Analytics agent for new deployments.

Memory trick: To bring on-prem to the cloud's secure arc, AMA is the mark.

More Mitigate threats using Microsoft Defender for Cloud questions