exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 2 question 29 discussion

Actual exam question from Microsoft's SC-200
Question #: 29
Topic #: 2
[All SC-200 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have Linux virtual machines on Amazon Web Services (AWS).
You deploy Azure Defender and enable auto-provisioning.
You need to monitor the virtual machines by using Azure Defender.
Solution: You manually install the Log Analytics agent on the virtual machines.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ejml
Highly Voted 2 years, 11 months ago
Wrong answer. it should be A. A machine with Azure Arc-enabled servers becomes an Azure resource and - when you've installed the Log Analytics agent on it - appears in Defender for Cloud with recommendations like your other Azure resources.
upvoted 11 times
xRiot007
4 months, 3 weeks ago
You need Azure Arc before the agent can be installed.
upvoted 3 times
...
Drui
2 years, 11 months ago
It's B because it doesn't mention Azure Arc, it just says Log analytics agent (which by the way is going to be deprecated and replaced by Azure monitor agent) https://docs.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-overview?tabs=PowerShellWindows
upvoted 12 times
Anonymousse
2 years, 7 months ago
But the Tip on that link says: Tip If you're onboarding machines running on Amazon Web Services (AWS), Defender for Cloud's connector for AWS transparently handles the Azure Arc deployment for you. Learn more in Connect your AWS accounts to Microsoft Defender for Cloud.
upvoted 1 times
Holii
2 years ago
SC-200 documentation says otherwise: https://learn.microsoft.com/en-us/training/modules/connect-non-azure-machines-to-azure-defender/4-connect-aws-accounts Complete Azure Arc prerequisites Make sure the appropriate Azure resources providers are registered: Microsoft.HybridCompute Microsoft.GuestConfiguration
upvoted 1 times
...
...
...
...
Nailik_Ms
Highly Voted 2 years, 2 months ago
Selected Answer: B
The question has few traps. 1. You have Linux machines on AWS. (don't specify if already onboarded) 2. You deploy a solution (Azure defender and enable auto provisioning) This doesn't mean any interaction with the previous Linux Machines. HERE: YOU NEED TO MONITOR THOSE VM WITH AZURE DEFENDER. meaning first we need to do the first step to monitor them, and that first step is not install the Log analytics agent. First we should enable Azure Arc on them. So I think answer is no B
upvoted 9 times
...
HAjouz
Most Recent 2 months ago
Selected Answer: A
Direct Agent Installation: You can directly install the Azure Monitor Agent (or the older Log Analytics agent) on a Linux VM running in AWS. This agent is the core component that collects logs and metrics. It's configured to send this data to your Azure Monitor workspace. This setup works independently of Azure Arc. The agent simply needs network connectivity to Azure.
upvoted 1 times
...
Dabinlo
3 months, 3 weeks ago
Selected Answer: A
I would say A, and this is from chatgpt: zure Defender requires the Log Analytics agent to monitor virtual machines. If you manually install the Log Analytics agent on the AWS Linux virtual machines and configure it to connect to an Azure Monitor Log Analytics workspace, Azure Defender can collect and analyze data from these machines. Key Details: Azure Arc is not required: Azure Arc simplifies management by onboarding non-Azure VMs as Azure resources, but it is not mandatory for Azure Defender to monitor AWS VMs. Auto-provisioning: When auto-provisioning is enabled, Azure Defender attempts to automatically install the Log Analytics agent on supported Azure VMs or Arc-enabled servers. If Azure Arc is not used, manual installation of the Log Analytics agent is a valid alternative.
upvoted 1 times
...
VeiN
6 months ago
OK so few things: 1. When auto-provisiong worked it worked with MMA agent (Log Analytcis Agent) which is not reliant on Azure Arc. Azure Arc works with AMA & could potentialy be auto-provisioned when ARC was installed (for instance by policy) which is current approach. Note there is also Multicloud connectors in preview on Azure Arc dashboard. 2. According to this link & checkup there is no auto-provisioning anymore therfore this question is outdated & broken. https://learn.microsoft.com/en-us/azure/defender-for-cloud/prepare-deprecation-log-analytics-mma-agent?WT.mc_id=Portal-Microsoft_Azure_Security#log-analytics-agent-autoprovisioning-experience---deprecation-plan
upvoted 1 times
...
uday1985
11 months, 3 weeks ago
https://learn.microsoft.com/en-us/azure/defender-for-cloud/faq-data-collection-agents
upvoted 1 times
...
Fedemend
1 year, 3 months ago
B. No Enabling auto-provisioning for Azure Defender means that the required monitoring agents, including the Log Analytics agent, will be automatically installed on the virtual machines. Therefore, there is no need to manually install the Log Analytics agent if auto-provisioning is enabled. The correct answer is "B. No."
upvoted 1 times
...
chepeerick
1 year, 6 months ago
Correct
upvoted 1 times
...
Marchiano
1 year, 9 months ago
Guys, I am now on MS Defender for Cloud (Getting started) and there is one option here called "Add non-Azure servers" with the following description: "Use the Log Analytics agent to extend Microsoft Defender for Cloud capabilities to servers running outside of Azure, including resources running on-premises and in other clouds." What are some of the MS Defender for Cloud extended capabilities? 1. Secure cloud application 2. Improve your security posture 3. Protect cloud workloads Please check also what the Log Analytics agent/extension is capable of, search on the web. "Azure Monitor Logs provides monitoring, alerting, and alert remediation capabilities across cloud and on-premises assets. [..] The extension installs the Log Analytics agent on Azure virtual machines, and enrolls virtual machines into an existing Log Analytics workspace." So even if it will be deprecated at some point in 2024, it is still a valid solution in the present.
upvoted 3 times
Marchiano
1 year, 9 months ago
A. Yes
upvoted 2 times
Doinitza
1 year, 8 months ago
Then, what is the purpose of Azure Arc?
upvoted 1 times
...
...
...
XLR8T2
1 year, 9 months ago
No es necesario instalar Log Analytics para monitorear, con Azure Arc es suficiente, respuesta B es la correcta.
upvoted 1 times
...
Sri534
2 years, 2 months ago
B is correct .. Explanation form ChatGPT No, manually installing the Log Analytics agent on the virtual machines is not the correct solution for monitoring the virtual machines using Azure Defender after enabling auto-provisioning. When Azure Defender is enabled with auto-provisioning, it automatically deploys the necessary monitoring agents on the virtual machines. In this case, since you have deployed Linux virtual machines on AWS, you would need to configure the Azure Defender for servers (Linux) solution to monitor these virtual machines. Once enabled, Azure Defender for servers (Linux) will automatically deploy the necessary monitoring agents on the virtual machines without the need for manual installation.
upvoted 3 times
...
Phantasm
2 years, 2 months ago
Selected Answer: B
B is correct. In order to monitor Linux virtual machines on AWS with Azure Defender, you need to install the Log Analytics agent manually on the virtual machines.
upvoted 2 times
...
Sango
2 years, 9 months ago
These are non-Azure, AWS PCs. You need to link the AWS environment using Azure Arc first.
upvoted 3 times
...
Lion007
2 years, 10 months ago
Selected Answer: B
B is Correct. The full correct answer should be "You enable Azure Arc to onboard the virtual machines to Azure Arc, then you enable auto-provisioning to install the Log Analytics agent on the virtual machines automatically."
upvoted 5 times
...
BlueLightRun
2 years, 11 months ago
Selected Answer: B
https://docs.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-machines?pivots=azure-portal There is a manual process for adding VMs
upvoted 1 times
...
StaxJaxson
2 years, 11 months ago
https://docs.microsoft.com/en-us/azure/defender-for-cloud/enable-data-collection?tabs=autoprovision-loganalytic
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago