AZ-500 · Question #202
You have an Azure subscription that contains the Azure Log Analytics workspaces shown in the following table. You create the virtual machines shown in the following table. You plan to use Azure…
The correct answer is C. VM1, VM2, VM3, and VM4. Explanation Option C is correct because Azure Sentinel (now Microsoft Sentinel) can connect to any virtual machine - regardless of operating system (Windows or Linux) or region - as long as it is connected to a Log Analytics workspace that has Sentinel enabled. The Microsoft…
Question
Exhibits
Options
- AVM1 only
- BVM1 and VM3 only
- CVM1, VM2, VM3, and VM4
- DVM1 and VM2 only
How the community answered
(40 responses)- A5% (2)
- B3% (1)
- C90% (36)
- D3% (1)
Explanation
Explanation
Option C is correct because Azure Sentinel (now Microsoft Sentinel) can connect to any virtual machine - regardless of operating system (Windows or Linux) or region - as long as it is connected to a Log Analytics workspace that has Sentinel enabled. The Microsoft Monitoring Agent (MMA) or Azure Monitor Agent can be installed on all supported VM types, enabling Sentinel to collect Windows Defender Firewall logs and other security data from all four VMs.
Options A, B, and D are incorrect because they incorrectly assume that limitations such as VM region, operating system type, or workspace location would prevent certain VMs from being connected to Sentinel. There is no requirement that the VM and the Log Analytics workspace must reside in the same region, nor is there a restriction based on VM size or OS version that would block connectivity.
Memory Tip: Think of Azure Sentinel as a universal collector - if a VM can run the Log Analytics agent and communicate with a Sentinel-enabled workspace, it can be monitored. Don't let table details about regions or VM types trick you into thinking connectivity is limited; focus on whether a Log Analytics workspace with Sentinel exists in the subscription.
Topics
Community Discussion
No community discussion yet for this question.

