AZ-801 · Question #145
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. Onboarding Server1 to Microsoft Defender for Endpoint does not solely meet the goal of collecting Windows Firewall logs in Microsoft Sentinel.
Question
Options
- AYes
- BNo
How the community answered
(23 responses)- A30% (7)
- B70% (16)
Why each option
Onboarding Server1 to Microsoft Defender for Endpoint does not solely meet the goal of collecting Windows Firewall logs in Microsoft Sentinel.
This option states "Yes", which is incorrect because onboarding to Microsoft Defender for Endpoint is not the direct method for collecting Windows Firewall logs via the specific data connector in Sentinel.
While Microsoft Defender for Endpoint can integrate with Microsoft Sentinel, its primary function is endpoint detection and response, not directly forwarding Windows Firewall logs via the dedicated Windows Firewall data connector, which typically relies on the Log Analytics agent for collection.
Concept tested: Sentinel Windows Firewall data collection
Source: https://learn.microsoft.com/en-us/azure/sentinel/connect-windows-firewall
Topics
Community Discussion
No community discussion yet for this question.