nerdexam
Microsoft

SC-100 · Question #230

You have an Azure subscription that contains a Microsoft Sentinel workspace. Your on-premises network contains firewalls that support forwarding event logs in the Common Event Format (CEF). There is n

Sign in or unlock SC-100 to reveal the answer and full explanation for question #230. The question stem and answer options stay visible for context.

Design security operations, identity, and compliance capabilities

Question

You have an Azure subscription that contains a Microsoft Sentinel workspace. Your on-premises network contains firewalls that support forwarding event logs in the Common Event Format (CEF). There is no built-in Microsoft Sentinel connector for the firewalls. You need to recommend a solution to ingest events from the firewalls into Microsoft Sentinel. What should you include in the recommendation?

Options

  • Aan Azure logic app
  • Ban on-premises Syslog server
  • Can on-premises data gateway
  • DAzure Data Factory

Unlock SC-100 to see the answer

You've previewed enough free SC-100 questions. Unlock SC-100 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Microsoft Sentinel#Log Ingestion#CEF#Security Operations
Full SC-100 Practice