You have three on-premises Windows Server 2019 machines: Server1 and Server2 on the internal network, and Server3 on the perimeter network. All servers have access to Azure. After installing the Windows Firewall data connector in Azure Sentinel, what must you do to collect Microsoft Defender Firewall data from these servers?
Choose an answer
Tap an option to check your answer.
Correct answer: Install the Microsoft Monitoring Agent on each server..
Why this is the answer
To collect Microsoft Defender Firewall data from on-premises Windows servers using the Windows Firewall data connector in Azure Sentinel, you must install the Microsoft Monitoring Agent (MMA) on each server. The MMA acts as a data collector, forwarding logs and performance data to Azure Monitor Log Analytics, which Azure Sentinel then uses. Creating an event subscription is a method for forwarding events between Windows servers, not for sending data to Azure Sentinel. The On-premises data gateway is used for connecting cloud services to on-premises data sources for services like Power BI, Power Apps, and Azure Logic Apps, not for collecting security logs for Azure Sentinel. Installing MMA only on internal servers and the data gateway on the perimeter server is incorrect because all servers need the MMA to send their firewall logs to Azure Sentinel.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed