nerdexam
Microsoft

AZ-500 · Question #202

You have an Azure subscription that contains the Azure Log Analytics workspaces shown in the following table. You create the virtual machines shown in the following table. You plan to use Azure…

The correct answer is C. VM1, VM2, VM3, and VM4. Explanation Option C is correct because Azure Sentinel (now Microsoft Sentinel) can connect to any virtual machine - regardless of operating system (Windows or Linux) or region - as long as it is connected to a Log Analytics workspace that has Sentinel enabled. The Microsoft…

Submitted by valeria.br· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure subscription that contains the Azure Log Analytics workspaces shown in the following table. You create the virtual machines shown in the following table. You plan to use Azure Sentinel to monitor Windows Defender Firewall on the virtual machines. Which virtual machines you can connect to Azure Sentinel?

Exhibits

AZ-500 question #202 exhibit 1
AZ-500 question #202 exhibit 2

Options

  • AVM1 only
  • BVM1 and VM3 only
  • CVM1, VM2, VM3, and VM4
  • DVM1 and VM2 only

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    90% (36)
  • D
    3% (1)

Explanation

Explanation

Option C is correct because Azure Sentinel (now Microsoft Sentinel) can connect to any virtual machine - regardless of operating system (Windows or Linux) or region - as long as it is connected to a Log Analytics workspace that has Sentinel enabled. The Microsoft Monitoring Agent (MMA) or Azure Monitor Agent can be installed on all supported VM types, enabling Sentinel to collect Windows Defender Firewall logs and other security data from all four VMs.

Options A, B, and D are incorrect because they incorrectly assume that limitations such as VM region, operating system type, or workspace location would prevent certain VMs from being connected to Sentinel. There is no requirement that the VM and the Log Analytics workspace must reside in the same region, nor is there a restriction based on VM size or OS version that would block connectivity.

Memory Tip: Think of Azure Sentinel as a universal collector - if a VM can run the Log Analytics agent and communicate with a Sentinel-enabled workspace, it can be monitored. Don't let table details about regions or VM types trick you into thinking connectivity is limited; focus on whether a Log Analytics workspace with Sentinel exists in the subscription.

Topics

#Azure Sentinel#Log Analytics#VM Monitoring#Connectivity

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice