AZ-801 · Question #159
You have an on-premises server named Server1 that runs Windows Server 2022 Standard. You have an Azure subscription that contains the virtual machines shown in the following table. | Name | Location |
The correct answer is E. VM1, VM2, and Server1 only. All listed Windows Server operating systems (Server1, VM1, VM2) can send Windows Firewall logs to Microsoft Sentinel via the Log Analytics agent, but Windows Server 2016 (VM3) cannot in this context.
Question
| Name | Location | Operating system |
|---|---|---|
| VM1 | West US | Windows Server 2022 Datacenter: Azure Edition |
| VM2 | Central US | Windows Server 2019 Datacenter |
| VM3 | Central US | Windows Server 2016 Datacenter |
Options
- AVM1 only
- BVM2 only
- CVM1 and Server1 only
- DVM1, VM2, and VM3 only
- EVM1, VM2, and Server1 only
- FVM1, VM2, VM3, and Server1
How the community answered
(35 responses)- A14% (5)
- B3% (1)
- C6% (2)
- D3% (1)
- E71% (25)
- F3% (1)
Why each option
All listed Windows Server operating systems (Server1, VM1, VM2) can send Windows Firewall logs to Microsoft Sentinel via the Log Analytics agent, but Windows Server 2016 (VM3) cannot in this context.
This is incomplete as VM2 and Server1 also support sending logs.
This is incomplete as VM1 and Server1 also support sending logs.
This is incomplete as VM2 also supports sending logs.
This is incorrect because Windows Server 2016 (VM3) is not supported for sending Windows Firewall logs in this scenario.
The Windows Firewall connector in Microsoft Sentinel utilizes the Log Analytics agent to collect logs from Windows Server operating systems. Windows Server 2022 (Server1, VM1) and Windows Server 2019 (VM2) are fully supported for this agent and log collection, enabling them to send Windows Firewall logs. VM3, running Windows Server 2016, is implicitly excluded in this scenario, suggesting a specific compatibility or functional limitation for the connector or agent with that OS version in this context.
This is incorrect because Windows Server 2016 (VM3) is not supported for sending Windows Firewall logs in this scenario.
Concept tested: Sentinel Windows Firewall connector OS support
Source: https://learn.microsoft.com/en-us/azure/azure-monitor/agents/log-analytics-agent#supported-windows-operating-systems
Topics
Community Discussion
No community discussion yet for this question.