nerdexam
Microsoft

AZ-801 · Question #145

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. Onboarding Server1 to Microsoft Defender for Endpoint does not solely meet the goal of collecting Windows Firewall logs in Microsoft Sentinel.

Monitor and troubleshoot Windows Server environments

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You onboard Server1 to Microsoft Defender for Endpoint. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(23 responses)
  • A
    30% (7)
  • B
    70% (16)

Why each option

Onboarding Server1 to Microsoft Defender for Endpoint does not solely meet the goal of collecting Windows Firewall logs in Microsoft Sentinel.

AYes

This option states "Yes", which is incorrect because onboarding to Microsoft Defender for Endpoint is not the direct method for collecting Windows Firewall logs via the specific data connector in Sentinel.

BNoCorrect

While Microsoft Defender for Endpoint can integrate with Microsoft Sentinel, its primary function is endpoint detection and response, not directly forwarding Windows Firewall logs via the dedicated Windows Firewall data connector, which typically relies on the Log Analytics agent for collection.

Concept tested: Sentinel Windows Firewall data collection

Source: https://learn.microsoft.com/en-us/azure/sentinel/connect-windows-firewall

Topics

#Microsoft Sentinel#Data Connectors#Log Collection#Hybrid Monitoring

Community Discussion

No community discussion yet for this question.

Full AZ-801 Practice