Your security team requires Windows Security event collection from Arc-enabled Windows servers and a one-time hardening script to run on 30 Arc-enabled Linux servers in a segmented network. No inbound ports can be opened. Which two extensions should you deploy?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Monitor Agent extension to the Windows servers, with a DCR that collects the required Security event channels., Custom Script Extension for Linux to run the hardening script from a secure storage location..
Why this is the answer
The Azure Monitor Agent (AMA) is the modern agent for collecting monitoring data from Azure VMs and Arc-enabled servers. It uses Data Collection Rules (DCRs) to specify what data to collect and where to send it, including Windows Security events. AMA communicates outbound, satisfying the "no inbound ports" requirement. The Custom Script Extension for Linux allows you to download and execute scripts on Arc-enabled Linux machines. This is ideal for running a one-time hardening script from a secure storage location, such as an Azure Storage account, and it also operates outbound. The Microsoft Monitoring Agent (MMA) is a legacy agent being deprecated. While it can collect security events, AMA is the recommended and more flexible solution. The Dependency Agent is used for discovering process dependencies and network connections, not for general event collection or running custom scripts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed