SC-200 · Question #292
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have a virtual machine named Server1 that runs Windows Server 2022 and is hosted in Amazon Web Services (AWS). You…
The correct answer is C. the Azure Connected Machine agent. To collect logs and resolve vulnerabilities for an AWS-hosted Windows Server 2022 VM using Defender for Cloud, the Azure Connected Machine agent must be installed first.
Question
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have a virtual machine named Server1 that runs Windows Server 2022 and is hosted in Amazon Web Services (AWS). You need to collect logs and resolve vulnerabilities for Server1 by using Defender for Cloud. What should you install first on Server1?
Options
- Athe Microsoft Monitoring Agent
- Bthe Azure Monitor agent
- Cthe Azure Connected Machine agent
- Dthe Azure Pipelines agent
How the community answered
(42 responses)- A2% (1)
- B5% (2)
- C81% (34)
- D12% (5)
Why each option
To collect logs and resolve vulnerabilities for an AWS-hosted Windows Server 2022 VM using Defender for Cloud, the Azure Connected Machine agent must be installed first.
The Microsoft Monitoring Agent (MMA) is a legacy agent primarily used for Log Analytics and Azure Security Center, but for onboarding hybrid machines and leveraging newer Defender for Cloud capabilities, the Azure Connected Machine agent is the foundational step.
The Azure Monitor agent is used for collecting guest OS logs and performance data, but it typically requires the machine to be already managed by Azure (e.g., via Azure Arc for hybrid machines), making the Azure Connected Machine agent the initial installation.
The Azure Connected Machine agent (part of Azure Arc) is required to onboard non-Azure machines (like those in AWS) to Azure, allowing them to be managed as Azure resources, which is a prerequisite for Defender for Cloud to collect logs and provide vulnerability assessments. This agent establishes connectivity to Azure Arc, enabling hybrid management capabilities.
The Azure Pipelines agent is used for running jobs in Azure DevOps pipelines and is unrelated to connecting a server for security management with Defender for Cloud.
Concept tested: Onboarding non-Azure servers to Defender for Cloud via Azure Arc
Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws
Community Discussion
No community discussion yet for this question.