exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 2 question 45 discussion

Actual exam question from Microsoft's SC-200
Question #: 45
Topic #: 2
[All SC-200 Questions]

You have an Azure subscription that uses Microsoft Defender for Cloud.

You have an Amazon Web Services (AWS) account that contains an Amazon Elastic Compute Cloud (EC2) instance named EC2-1.

You need to onboard EC2-1 to Defender for Cloud.

What should you install on EC2-1?

  • A. the Log Analytics agent
  • B. the Azure Connected Machine agent
  • C. the unified Microsoft Defender for Endpoint solution package
  • D. Microsoft Monitoring Agent
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 2 years, 2 months ago
Selected Answer: B
To onboard an Amazon Elastic Compute Cloud (EC2) instance to Microsoft Defender for Cloud, you should install the Azure Connected Machine agent on the instance. Therefore, the correct answer is B.
upvoted 11 times
...
user636
Most Recent 8 months, 1 week ago
Selected Answer: B
Azure Connected Machine agent is the first step to onboard any non-azure device to azure. The ACM agent can be used to deploy LA agent & other extensions. Ref: https://learn.microsoft.com/en-us/training/modules/connect-non-azure-machines-to-azure-defender/3-connect-non-azure-machines Ref: https://learn.microsoft.com/en-us/training/modules/connect-non-azure-machines-to-azure-defender/4-connect-aws-accounts
upvoted 2 times
...
wheeldj
1 year ago
Just to throw more confusion into this question you can also connect non-Azure machines to Defender for Cloud directly using the Defender for Endpoint Agent which offers a single unified solution. Sounds like answer C to anyone else? https://learn.microsoft.com/en-us/azure/defender-for-cloud/onboard-machines-with-defender-for-endpoint D is definitely not correct, but I think there is an argument for A, B and C. I agree B is probably the most obvious answer, but who knows what's in the head of the Microsoft Examiners!!
upvoted 2 times
user636
8 months, 1 week ago
The question does not mention that you have the M365 Defender subscription/license. Don't assume stuff, this is an exam. C cannot be the answer to this question.
upvoted 2 times
...
...
KRAKE3N
1 year ago
Selected Answer: A (after installing Arc to onboard the vm from another cloud or on-premise) you should install the Log Analytics agent( to be replaced with Azure Monitoring Agent this year, id recommend install AMA for obvious reason but to answer this question, the answer should be A)
upvoted 1 times
...
kazaki
1 year, 2 months ago
Outdated but B
upvoted 3 times
...
estyj
1 year, 3 months ago
To onboard AWS EC2 you would need the B. the Azure connected Machine agent.
upvoted 1 times
...
chepeerick
1 year, 6 months ago
Incorrect, option B, he Azure Connected Machine agent is used to connect and manage non-Azure machines (in this case, the EC2 instance) with Microsoft Defender for Cloud. It allows you to monitor and protect non-Azure resources in your environment.
upvoted 3 times
...
cris_exam
1 year, 7 months ago
Selected Answer: A
Well... if the question would have mentioned ARC anywhere, I would have totally agreed with B: Connected Machine agent https://learn.microsoft.com/en-us/azure/azure-arc/servers/learn/quick-enable-hybrid-vm#install-the-agent-using-the-script BUT... there is an option without ARC and as the question is neutral about the onboarding flavor, it makes the answer to be A: Log Analytics in my opinion. https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-machines#connect-on-premises-machines-by-using-the-azure-portal
upvoted 4 times
kabooze
1 year, 6 months ago
they're deprecating LA agent though... It all depends on when these questions were made and with which solution in mind, but i'd say "B"
upvoted 3 times
Ramye
1 year, 2 months ago
LA Agent is still valid as Defender for Cloud and has the same name as of now - 9 Feb 2024), however, the Log Analytics agent (also known as MMA) is on a deprecation path and will be retired in Aug 2024.
upvoted 1 times
...
...
Gurulee
1 year, 3 months ago
what he/she said ;-) Azure Monitor agent to replace LA agent
upvoted 1 times
...
...
glauciasdiniz
1 year, 7 months ago
The answer corret is letter ---> C Microsoft Defender for Endpoint integrates seamlessly with Microsoft Defender for Servers. You can onboard servers automatically, have servers monitored by Microsoft Defender for Cloud appear in Defender for Endpoint, and conduct detailed investigations as a Microsoft Defender for Cloud customer. For more information please go to Protect your endpoints with Defender for Cloud's integrated EDR solution: Microsoft Defender for Endpoint https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-server-endpoints?view=o365-worldwide
upvoted 1 times
...
Stfnl
1 year, 8 months ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/azure-arc/servers/agent-overview The Azure Connected Machine agent enables you to manage your Windows and Linux machines hosted outside of Azure on your corporate network or other cloud providers.
upvoted 2 times
...
Marchiano
1 year, 9 months ago
Selected Answer: B
A & D are the same thing, C is out of context, while Azure Connected Machine agent = Azure Arc "We recommend that you use the auto-provisioning process to install Azure Arc on all of your existing and future EC2 instances. To enable the Azure Arc auto-provisioning, you need Owner permission on the relevant Azure subscription." Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws
upvoted 3 times
...
theplaceholder
1 year, 9 months ago
Selected Answer: B
ARC it up
upvoted 3 times
...
EM1234
1 year, 9 months ago
Selected Answer: B
You're going to need defender for servers which needs ARC. So choice B makes the most sense. Also A and D are the same thing, and yes they are "legacy". The log analytics agent has been called OMS (the code came from it) and also the Microsoft Monitoring agent. This is different than the Azure monitor agent, which has a whole new code base and features. Link for choosing B: https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws#defender-for-servers Hope this helps.
upvoted 3 times
...
teouba
2 years ago
Selected Answer: B
Answer is B Please check the video below at 04:15 As you can see, server is already onboarded using Azure Arc agent and there is a recommendation to also install Log Analytics agent. So FIRST you need to install Arc agent https://www.youtube.com/watch?v=uogTZe6p7nc
upvoted 4 times
danb67
1 year, 6 months ago
Agree with B
upvoted 1 times
...
...
torvy
2 years ago
Answer is D, you should install MMA on EC2
upvoted 1 times
...
haskelatchi
2 years ago
The answer is D. Log analytics agent is legacy. https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-migration
upvoted 2 times
...
cosmin_mm
2 years, 1 month ago
Selected Answer: A
Forgot to vote :)
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago