How to On-Prem VMs Forward Events to Azure Sentinel?
You have 20 on-premises virtual machines that run Windows Server. You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace1. You need to collect events from the on-premises virtual machines end forward the events to Workspace1. The solution must ensure that you can define filters to minimize the volume of collected events. Which two components should you install on each virtual machine? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Community Votes
50% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the pairing of monitoring agents for direct Sentinel ingestion, while the common trap involves confusing legacy extension deployment with mandatory Azure Arc onboarding requirements.
This question evaluates hybrid log collection strategies for on-premises Windows servers forwarding telemetry to Azure Sentinel. Community discussion reveals a split between traditional workspace extensions and modern Azure Arc-dependent agent stacks.
Selecting the Azure Connected Machine agent and Azure Monitor agent (AC) due to modern hybrid best practices, which overlooks the exam’s reliance on direct Log Analytics extension compatibility.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Azure Monitor agent (Option C) replaces legacy collectors and supports advanced data filtering to reduce event volume before transmission. Paired with the Log Analytics VM extension (Option D), it establishes a secure channel directly to Workspace1 without requiring additional platform services. This combination satisfies the exam's requirement for minimizing collected events while ensuring reliable ingestion into Azure Sentinel.Why the Other Options Are Wrong
Option A enables Azure Arc management but does not natively handle security event filtering or direct Sentinel routing in this context. Options B and E focus exclusively on application dependency mapping and network topology visualization, making them irrelevant for operational log collection. Consequently, these components fail to meet the core telemetry forwarding and filtering objectives outlined in the scenario.Community Comment Notes
Candidates remain divided between CD and AC, reflecting real-world architectural shifts toward Azure Arc. Comment [2] and [3] correctly note that production environments typically require the Connected Machine agent to enable AMA deployment on non-Azure resources. Meanwhile, Comment [1] and [5] emphasize that the Log Analytics VM extension remains a valid exam pathway for direct workspace connectivity. This discrepancy highlights the importance of recognizing legacy versus modern hybrid monitoring patterns in certification contexts.Official Reference
Exam Strategy
When reviewing hybrid monitoring questions, carefully distinguish between direct workspace extensions and Azure Arc-dependent agent deployments. Prioritize options that explicitly mention filter capabilities and direct Sentinel connectivity, as exam scenarios often test practical data reduction techniques over theoretical onboarding steps.