exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 4 question 61 discussion

Actual exam question from Microsoft's AZ-500
Question #: 61
Topic #: 4
[All AZ-500 Questions]

HOTSPOT -
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.

You have an Azure subscription named Subscription2 that contains the following resources:
✑ An Azure Sentinel workspace
✑ An Azure Event Grid instance
You need to ingest the CEF messages from the NVA1 to Azure Sentinel.
What should you configure for each subscription? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jpons
Highly Voted 3 years, 4 months ago
Logs analytics agent and Sentinel data connector https://docs.microsoft.com/en-us/azure/sentinel/connect-cef-agent?tabs=rsyslog
upvoted 55 times
AzureJobsTillRetire
1 year, 9 months ago
Correct. The Sentinel data connector to choose is Common Event Format (CEF) via AMA (Azure Monitor Agent)
upvoted 1 times
...
Custodian
2 years, 6 months ago
The link you send says the following: Configuration - You must have elevated permissions (sudo) on your designated Linux machine. - The Linux machine must not be connected to any Azure workspaces before you install the Log Analytics agent.
upvoted 1 times
...
...
Muaamar_Alsayyad
Highly Voted 2 years ago
An Azure Log Analytics agent on a Linux virtual machine Sentinel Connector
upvoted 10 times
...
stonwall12
Most Recent 2 months, 3 weeks ago
NOTE: The CEF/Syslog collection method using a Linux VM as a forwarder is now considered a legacy approach. The current recommended method is to use Azure Arc-enabled servers with the Azure Monitor agent (AMA) for collecting CEF/Syslog logs from network appliances. Answer: Subscription1: An Azure Log Analytics agent on a Linux virtual machine Subscription2: A new Azure Sentinel data connector Reason: - Subscription1, we need a Linux VM with the Log Analytics agent to act as a CEF forwarder for the NVA's security events - Subscription2, which contains the Sentinel workspace, we need to configure a Sentinel data connector to receive the CEF logs Reference: https://learn.microsoft.com/en-us/azure/sentinel/connect-common-event-format https://learn.microsoft.com/en-us/azure/sentinel/connect-log-forwarder
upvoted 1 times
...
golitech
3 months ago
Subscription 1: Set up Event Hub Namespace to collect CEF messages from the NVA. Subscription 2: Set up Azure Sentinel Data Connector to pull data from the Event Hub in Subscription 1. Event Hub Namespace: The Event Hub will collect the CEF messages from the NVA. Why?: You need an Event Hub to ingest CEF logs from the NVA in Subscription 1, as CEF messages are typically sent to a centralized event hub. Event Hub can handle high-throughput events and stream them for further processing. Azure Sentinel Data Connector: Sentinel provides a specific data connector for Event Hub logs that can pull logs from Event Hub into the Sentinel workspace. Why?: You need to connect Azure Sentinel to the Event Hub in Subscription 1 to collect the CEF logs. The Azure Sentinel Data Connector will enable this integration.
upvoted 1 times
...
Pamban
6 months ago
CEF= Linux VM Hence answer is An Azure Log Analytics agent on a Linux virtual machine Sentinel Connector Link: https://learn.microsoft.com/en-us/azure/sentinel/connect-common-event-format
upvoted 3 times
...
wardy1983
1 year ago
Logs analytics agent and Sentinel data connector https://docs.microsoft.com/en-us/azure/sentinel/connect-cef-agent?tabs=rsyslog
upvoted 1 times
...
heatfan900
1 year, 2 months ago
YOU NEED AGENT ON THE NVA WHICH IS SENDING DATA IN CEF WHICH IS CLASSIC FOR LINUX AND THE DATA CONNECTOR ON THE SENTINEL SIDE WHICH IS NEEDED FOR IT TO CONNECT TO THE AGENT. EVERYTHING ELSE IS THERE TO THROW YOU OFF.
upvoted 1 times
...
Self_Study
1 year, 3 months ago
On an exam on 7/8/23, Log analytics agent sentinel connector
upvoted 3 times
...
Pupu86
1 year, 4 months ago
https://learn.microsoft.com/en-us/azure/sentinel/connect-common-event-format Linux VM with LAA Azure Sentinel Workspace (LAW)
upvoted 1 times
...
zellck
1 year, 6 months ago
1. Azure Log Analytics agent 2. Azure Sentinel data connector https://learn.microsoft.com/en-us/azure/sentinel/connect-cef-ama
upvoted 5 times
...
majstor86
1 year, 8 months ago
An Azure Log Analytics agent on a Linux virtual machine A new Azure Sentinel Data Connector
upvoted 4 times
...
Khasan
1 year, 9 months ago
In exam 11/02/2023. This is the correct answer.
upvoted 3 times
...
serget12
2 years, 1 month ago
I don't see a Linux VM in the resources, so not sure why that is an option for 1. And if you don't have that option, then you need workspace.
upvoted 1 times
serget12
2 years, 1 month ago
Sorry, you need a connector for the workspace. for Sentinel, first thing it looks for is a workspace, then you can add the connector.
upvoted 1 times
...
...
SilentH
2 years, 6 months ago
1st box: An Azure Log Analytics agent on a Linux virtual machine 2nd box: A new Azure Log Analytics workspace This is somewhat confusing but I believe the above answers are correct because the Azure LA agent can stream directly to Sentinel without need of a Sentinal connector. And, Sentinel needs a LA workspace to store its data into.
upvoted 1 times
chikorita
1 year, 8 months ago
Sentinel workspace is nothing but LAW which already exists
upvoted 1 times
...
...
Eltooth
2 years, 7 months ago
Log Analytics Agent & workspace
upvoted 1 times
...
subhuman
2 years, 8 months ago
Answer provided is wrong Box 1 You need an Azure log analytics Agent Box 2 you need a data connector
upvoted 3 times
...
divyateja322
2 years, 9 months ago
https://docs.microsoft.com/en-us/azure/sentinel/connect-common-event-format Box1: log analytics agent Box2: sentiner data connector
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago