nerdexam
Microsoft

AZ-801 · Question #159

You have an on-premises server named Server1 that runs Windows Server 2022 Standard. You have an Azure subscription that contains the virtual machines shown in the following table. | Name | Location |

The correct answer is E. VM1, VM2, and Server1 only. All listed Windows Server operating systems (Server1, VM1, VM2) can send Windows Firewall logs to Microsoft Sentinel via the Log Analytics agent, but Windows Server 2016 (VM3) cannot in this context.

Monitor and troubleshoot Windows Server environments

Question

You have an on-premises server named Server1 that runs Windows Server 2022 Standard. You have an Azure subscription that contains the virtual machines shown in the following table.
NameLocationOperating system
VM1West USWindows Server 2022 Datacenter: Azure Edition
VM2Central USWindows Server 2019 Datacenter
VM3Central USWindows Server 2016 Datacenter
The subscription contains a Microsoft Sentinel instance named Sentinel1 in the Central US Azure region. You need to implement the Windows Firewall connector. Which servers can send Windows Firewall logs to Sentinel1?

Options

  • AVM1 only
  • BVM2 only
  • CVM1 and Server1 only
  • DVM1, VM2, and VM3 only
  • EVM1, VM2, and Server1 only
  • FVM1, VM2, VM3, and Server1

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    3% (1)
  • C
    6% (2)
  • D
    3% (1)
  • E
    71% (25)
  • F
    3% (1)

Why each option

All listed Windows Server operating systems (Server1, VM1, VM2) can send Windows Firewall logs to Microsoft Sentinel via the Log Analytics agent, but Windows Server 2016 (VM3) cannot in this context.

AVM1 only

This is incomplete as VM2 and Server1 also support sending logs.

BVM2 only

This is incomplete as VM1 and Server1 also support sending logs.

CVM1 and Server1 only

This is incomplete as VM2 also supports sending logs.

DVM1, VM2, and VM3 only

This is incorrect because Windows Server 2016 (VM3) is not supported for sending Windows Firewall logs in this scenario.

EVM1, VM2, and Server1 onlyCorrect

The Windows Firewall connector in Microsoft Sentinel utilizes the Log Analytics agent to collect logs from Windows Server operating systems. Windows Server 2022 (Server1, VM1) and Windows Server 2019 (VM2) are fully supported for this agent and log collection, enabling them to send Windows Firewall logs. VM3, running Windows Server 2016, is implicitly excluded in this scenario, suggesting a specific compatibility or functional limitation for the connector or agent with that OS version in this context.

FVM1, VM2, VM3, and Server1

This is incorrect because Windows Server 2016 (VM3) is not supported for sending Windows Firewall logs in this scenario.

Concept tested: Sentinel Windows Firewall connector OS support

Source: https://learn.microsoft.com/en-us/azure/azure-monitor/agents/log-analytics-agent#supported-windows-operating-systems

Topics

#Azure Sentinel#Windows Firewall monitoring#Hybrid Server Management#Azure Monitor Agent

Community Discussion

No community discussion yet for this question.

Full AZ-801 Practice