AZ-500 · Question #208
You are collecting events from Azure virtual machines to an Azure Log Analytics workspace. You plan to create alerts based on the collected events. You need to identify which Azure services can be…
The correct answer is A. Azure Monitor D. Azure Sentinel. To create alerts based on events collected from Azure VMs in a Log Analytics workspace, you should identify Azure Monitor and Azure Sentinel.
Question
Options
- AAzure Monitor
- BAzure Security Center
- CAzure Analytics Services
- DAzure Sentinel
- EAzure Advisor
How the community answered
(30 responses)- A80% (24)
- B10% (3)
- C7% (2)
- E3% (1)
Why each option
To create alerts based on events collected from Azure VMs in a Log Analytics workspace, you should identify Azure Monitor and Azure Sentinel.
Azure Monitor is the primary service for collecting, analyzing, and acting on telemetry from Azure and on-premises environments, including creating alerts based on log data from Log Analytics workspaces.
Microsoft Defender for Cloud (formerly Azure Security Center) provides security posture management and threat protection, primarily generating its own security alerts rather than being the direct platform for creating custom alerts from raw Log Analytics events for general monitoring.
Azure Analytics Services is a general term for various data analytics platforms and is not specifically designed for creating operational alerts from Log Analytics workspace data.
Azure Sentinel is a Security Information and Event Management (SIEM) solution built on Azure Log Analytics, which allows you to create analytics rules (alerts) based on ingested security data and events.
Azure Advisor provides personalized recommendations for optimizing Azure resources, but it is not used to create alerts from log data.
Concept tested: Alerting from Log Analytics with Azure Monitor and Sentinel
Source: https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/alerts-unified-log, https://learn.microsoft.com/en-us/azure/sentinel/detect-threats-built-in
Topics
Community Discussion
No community discussion yet for this question.