After enabling Microsoft Defender for Servers Plan 2, which resource must you create first to implement File Integrity Monitoring (FIM)?
Choose an answer
Tap an option to check your answer.
Correct answer: a Log Analytics workspace.
Why this is the answer
To implement File Integrity Monitoring (FIM) with Microsoft Defender for Servers Plan 2, a Log Analytics workspace is the foundational resource you must create first. FIM relies on the Azure Monitor Agent (AMA) sending event data to a Log Analytics workspace for collection, analysis, and alerting. Without a workspace, there's no destination for the FIM data. A private endpoint is for secure network connectivity, not data storage or analysis. A storage account is for general data storage, but FIM specifically uses Log Analytics for its operational data. A data collection rule (DCR) defines what data to collect and where to send it, but it requires an existing Log Analytics workspace as its target.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed