You need to detect and alert on changes to C:\Windows\System32 and to the HKLM\Software\Company registry path on Windows Servers. You use Microsoft Defender for Servers Plan 2 and want alerts to appear in Defender for Cloud and logs in a Log Analytics workspace. What should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Ensure servers report to a Log Analytics workspace with Defender for Servers Plan 2. In Defender for Cloud > Environment settings > the workspace > File integrity monitoring, add the folder and registry paths and enable alerting..
Why this is the answer
This option correctly leverages Microsoft Defender for Servers Plan 2's built-in File Integrity Monitoring (FIM) capability. FIM allows you to monitor changes to critical files and registry paths, with alerts appearing in Defender for Cloud and logs sent to the associated Log Analytics workspace. The other options are incorrect because: Azure Monitor Activity Log alerts track control plane operations, not file/registry changes within a VM. Qualys is a third-party solution, not the integrated Microsoft approach for Defender for Servers. Update Management focuses on patching, not real-time file/registry monitoring. While Sysmon can detect these changes, it requires manual configuration and integration for alerting, and isn't the primary integrated solution offered by Defender for Servers Plan 2 for this specific requirement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed