nerdexam
Microsoft

AZ-500 · Question #277

Hotspot Question You have an Azure subscription named Subscription1 that contains the resources shown in the following table. You have an Azure subscription named Subscription2 that contains the…

The correct answer is The configuration for Subscription1 to ingest CEF messages from NVAs to Azure Sentinel is 'An Event Hubs namespace'. = Yes; The configuration for Subscription2 to ingest CEF messages from NVAs to Azure Sentinel is 'A new Azure Log Analytics workspace'. = Yes. To ingest CEF (Common Event Format) messages from NVAs (Network Virtual Appliances) in Subscription1 into Azure Sentinel in Subscription2, an Event Hubs namespace is required in Subscription1 to act as a cross-subscription data relay/pipeline, since Azure Sentinel cannot…

Submitted by akirajp· Mar 6, 2026Configure SIEM and threat detection solutions / Manage security monitoring with Microsoft Sentinel (SC-200 / AZ-500 Security Domain)

Question

Hotspot Question You have an Azure subscription named Subscription1 that contains the resources shown in the following table. You have an Azure subscription named Subscription2 that contains the following resources: - An Azure Sentinel workspace - An Azure Event Grid instance You need to ingest the CEF messages from the NVAs to Azure Sentinel. What should you configure for each subscription? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-500 question #277 exhibit 1
AZ-500 question #277 exhibit 2

Answer Area

  • The configuration for Subscription1 to ingest CEF messages from NVAs to Azure Sentinel is 'An Event Hubs namespace'.Yes
  • The configuration for Subscription2 to ingest CEF messages from NVAs to Azure Sentinel is 'A new Azure Log Analytics workspace'.Yes

Explanation

To ingest CEF (Common Event Format) messages from NVAs (Network Virtual Appliances) in Subscription1 into Azure Sentinel in Subscription2, an Event Hubs namespace is required in Subscription1 to act as a cross-subscription data relay/pipeline, since Azure Sentinel cannot directly pull logs from resources in a different subscription without an intermediary. In Subscription2, a new Azure Log Analytics workspace is needed because Azure Sentinel requires its own dedicated Log Analytics workspace to store and analyze ingested security data - the existing Event Grid instance in Subscription2 is not sufficient for log ingestion and storage. This architecture follows the standard CEF-over-Event-Hubs pattern for cross-subscription Sentinel data ingestion.

Topics

#Azure Sentinel#CEF Log Ingestion#Event Hubs#Log Analytics Workspace

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice