You have an on-premises Server1 (Windows Server 2022) and several Azure VMs. Microsoft Sentinel1 is deployed in Central US. Which of the listed machines can send Windows Firewall logs to Sentinel1?
Choose an answer
Tap an option to check your answer.
Correct answer: VM1, VM2, and Server1 only.
Why this is the answer
Microsoft Sentinel can collect logs from both Azure VMs and on-premises servers. For Azure VMs (VM1, VM2, VM3), you typically use the Azure Monitor Agent (AMA) or Log Analytics agent to forward Windows Firewall logs to a Log Analytics workspace, which Sentinel then ingests. For an on-premises server like Server1 (Windows Server 2022), you would install the Azure Monitor Agent (AMA) or Log Analytics agent directly on the server to send its logs to the same Log Analytics workspace. Therefore, all listed machines (VM1, VM2, and Server1) can be configured to send Windows Firewall logs to Sentinel1. The option "VM1, VM2, and VM3 only" is incorrect because Server1 can also send logs. The other options are incorrect because they exclude machines that can send logs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed