nerdexam
Microsoft

SC-100 · Question #107

A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription. All the on-premises servers in the perimeter network are prevented from…

The correct answer is C. Implement resource-based role-based access control (RBAC) in Microsoft Sentinel. D. Use the Azure Monitor agent with the multi-homing configuration. Two configurations are needed to satisfy the dual-team access requirements. C (Resource-based RBAC in Microsoft Sentinel): Resource-context RBAC allows access to Sentinel data to be scoped based on the Azure resources a user has permissions to. This means the IT operations team…

Design security operations, identity, and compliance capabilities

Question

A customer has a hybrid cloud infrastructure that contains a Microsoft 365 E5 subscription and an Azure subscription. All the on-premises servers in the perimeter network are prevented from connecting directly to the internet. The customer recently recovered from a ransomware attack. The customer plans to deploy Microsoft Sentinel. You need to recommend configurations to meet the following requirements:

  • Ensure that the security operations team can access the security logs

and the operation logs.

  • Ensure that the IT operations team can access only the operations

logs, including the event logs of the servers in the perimeter network. Which two configurations can you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • AConfigure Azure Active Directory (Azure AD) Conditional Access policies.
  • BCreate a custom collector that uses the Log Analytics agent.
  • CImplement resource-based role-based access control (RBAC) in Microsoft Sentinel.
  • DUse the Azure Monitor agent with the multi-homing configuration.

How the community answered

(44 responses)
  • A
    14% (6)
  • B
    30% (13)
  • C
    57% (25)

Explanation

Two configurations are needed to satisfy the dual-team access requirements. C (Resource-based RBAC in Microsoft Sentinel): Resource-context RBAC allows access to Sentinel data to be scoped based on the Azure resources a user has permissions to. This means the IT operations team can be granted access only to the Log Analytics workspace resources (specifically the Windows event logs from perimeter servers) without seeing security logs, while the security operations team retains full access. D (Azure Monitor Agent with multi-homing): The perimeter network servers cannot connect directly to the internet, so the legacy Log Analytics (MMA) agent or a direct internet connection won't work. The Azure Monitor Agent supports multi-homing - sending data to multiple Log Analytics workspaces simultaneously - and can be configured to work through a Log Analytics Gateway or Azure Arc, enabling collection from isolated perimeter servers. Option A (Conditional Access) controls authentication, not log access. Option B (custom collector with Log Analytics agent) is the legacy approach and does not solve the dual-workspace or access-scoping requirement.

Topics

#Microsoft Sentinel#Log Collection#Role-Based Access Control (RBAC)#Hybrid Cloud Security

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice