You have several virtual machines and multiple Log Analytics workspaces. You plan to use Azure Sentinel to monitor Windows Defender Firewall on the virtual machines. Which virtual machines can you connect to Azure Sentinel?
Choose an answer
Tap an option to check your answer.
Correct answer: VM1, VM2, VM3, and VM4.
Why this is the answer
Azure Sentinel can connect to any virtual machine (VM) that sends its logs to a Log Analytics workspace, regardless of the VM's operating system or its location (on-premises or in Azure). The key requirement is that the VM has the Log Analytics agent installed and configured to send data to a workspace that Azure Sentinel is connected to. Since all listed VMs (VM1, VM2, VM3, and VM4) are sending their logs to a Log Analytics workspace, they can all be monitored by Azure Sentinel for Windows Defender Firewall events, assuming the necessary data connectors are enabled in Sentinel.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed