exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 2 question 22 discussion

Actual exam question from Microsoft's SC-200
Question #: 22
Topic #: 2
[All SC-200 Questions]

You create an Azure subscription.
You enable Azure Defender for the subscription.
You need to use Azure Defender to protect on-premises computers.
What should you do on the on-premises computers?

  • A. Install the Log Analytics agent.
  • B. Install the Dependency agent.
  • C. Configure the Hybrid Runbook Worker role.
  • D. Install the Connected Machine agent.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Eltooth
Highly Voted 3 years, 8 months ago
Correct - A
upvoted 15 times
...
Haha0010
Highly Voted 2 years, 4 months ago
Selected Answer: A
In exam today (16 jan 2023)
upvoted 13 times
...
OneplusOne
Most Recent 2 weeks, 3 days ago
Selected Answer: D
It's right here: https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-machines?form=MG0AV3
upvoted 2 times
...
vbcentralsoc
3 weeks, 3 days ago
Selected Answer: D
✅ Correct Answer: D. Install the Connected Machine agent
upvoted 2 times
...
9802f06
1 month, 1 week ago
Selected Answer: A
CoPilot answer is: A The Log Analytics agent enables on-premises computers to communicate with Azure Security Center. This agent collects security data and sends it to Azure Security Center.
upvoted 1 times
...
HAjouz
2 months ago
Selected Answer: D
While installing the Log Analytics agent (A) directly can onboard machines for some Defender for Cloud capabilities via a Log Analytics workspace, the standard and more integrated modern approach is to use Azure Arc. Installing the Connected Machine agent (D) brings the server under Azure management via Arc, which then facilitates the deployment and management of Defender for Cloud components.
upvoted 3 times
...
xRiot007
5 months, 4 weeks ago
Selected Answer: A
You need to do monitoring and then have Defender react, so A - Log Analytics (or AMA, today) is enough. You don't have to do centralized management in this question.
upvoted 1 times
xRiot007
4 months, 1 week ago
Changed my mind - it's D - install the connected machine. Without Arc, we cannot install any extension on-prem, and the agent (LA or AMA) is installed via an extension. Ref: https://learn.microsoft.com/en-us/azure/azure-arc/servers/manage-vm-extensions
upvoted 3 times
...
...
VeiN
7 months, 1 week ago
Selected Answer: D
You need to install Azure Arc (azure connected Machine). In short this will create an azure resource representation of onpremise machine that can be partialy managed like azure resources. For instance you can run DfC Regulatory compliance.
upvoted 4 times
...
ZECO85
9 months ago
Selected Answer: A
The Connected Machine agent (Option D) is used to connect and manage machines that are hosted outside of Azure, such as on-premises or other cloud providers, through Azure Arc12. While it helps in managing these machines, it does not specifically enable the security features provided by Azure Defender. For Azure Defender to analyze and provide security recommendations, the Log Analytics agent is required. This agent collects data from your on-premises machines and sends it to Azure Monitor, which Azure Defender uses for its security analysis. So the answer is A
upvoted 3 times
...
e072f83
11 months, 2 weeks ago
in order to make the Log analytics agent work, you first need the arc agent on an on-prem server (formerly connected machine agent) so D is correct. https://learn.microsoft.com/en-us/azure/defender-for-cloud/monitoring-components
upvoted 2 times
...
DChilds
1 year, 1 month ago
Selected Answer: A
Azure Defender (now named Defender for Cloud) relies on Log Analytics Agent to collect logs and enable protection of the workstations.
upvoted 2 times
...
DChilds
1 year, 1 month ago
Selected Answer: D
Question may be outdated but installing Azure Arc is the first thing to do with an on-prem server. This will ensure you can deploy Azure services like Defender and manage it from the Defender portal. Installing Log Analytics will be to view the Windows logs in a portal like Sentinel so as to be build alerts and rules from those logs. Azure Arc (previously Connected Machine agent) has to be loaded first.
upvoted 3 times
DChilds
1 year, 1 month ago
I change my mind, Azure Defender relies on the Log Analytic Agent to collect logs for monitoring, threat detection etc. Answer is A.
upvoted 2 times
...
...
Ramye
1 year, 3 months ago
This is an outdated question but don’t understand why most saying A as they answer? It makes sense D. Install the Connected Machine agent. Thoughts???
upvoted 1 times
Ramye
1 year, 3 months ago
Never mind @trashbox explained below …thx
upvoted 2 times
...
...
kazaki
1 year, 3 months ago
Selected Answer: D
Outdated question now using arc only for defender for cloud
upvoted 2 times
...
kazaki
1 year, 3 months ago
this is outdated
upvoted 1 times
...
kabooze
1 year, 7 months ago
Selected Answer: D
this should be D. For defender to work you need the azure arc agent (or azure connected .... agent) to make it work. Although, there IS a possibility to deploy it directly without using Arc, but that's not the point of this question.
upvoted 3 times
...
slurppp
1 year, 7 months ago
Think many of these questions are now out of date. Log Analytics Agent is now legacy and is replaced as "Azure Monitor Agent (AMA)" - Examptopics needs to update this whole course I think. Too many things have changed names now so I would expect the exam questions to be different or updated.
upvoted 5 times
Ramye
1 year, 3 months ago
Exactly. And Microsoft announced the below "The English language version of this exam will be updated on March 4, 2024. Review the study guide linked in the “Tip” box for details on upcoming changes. If a localized version of this exam is available, it will be updated approximately eight weeks after this date. While Microsoft makes every effort to update localized versions as noted, there may be times when the localized versions of this exam are not updated on this schedule" Source: https://learn.microsoft.com/en-us/credentials/certifications/exams/sc-200/
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...