FEFreeExamDumps.in

Microsoft Cybersecurity Architect

Topic 3

Question 184

SC-100 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have 1,000 on-premises servers that run Linux. You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1 and 1,000 virtual machines that run Linux. All the on-premises Linux servers are onboarded to Azure Arc. You plan to collect Common Event Format (CEF) logs by using the Azure Monitor Agent connector in Microsoft Sentinel. You need to design a solution for collecting specific events from the logs. The solution must meet the following requirements: • Minimize the number of Microsoft Entra ID identities required. • Minimize the number of events delivered to WS1. • Ensure that all the required events are ingested. • Minimize administrative effort. What should you include in the solution? To answer, select the options in the answer area. NOTE: Each correct answer is worth one point.

Question 184