Option A looks right. Installing the Log Analytics agent is what allows on-prem servers to send event data, including firewall logs, to Sentinel via the linked workspace. I remember seeing similar steps in the official study guide and practice labs. Pretty sure about this, but if anyone's seen it done another way let me know.
Q: 2
Note: This question is part of a series of questions that present the same scenario. Each question in
the series contains a unique solution that might meet the stated goals. Some question sets might
have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these
questions will not appear in the review screen.
You have an on-premises server named Server1 that runs Windows Server.
You have a Microsoft Sentinel instance.
You add the Windows Firewall data connector in Microsoft Sentinel.
You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1.
Solution: You install the Log Analytics agent on Server1
Does this meet the goal?
Options
Discussion
Its A. Installing the Log Analytics agent on Server1 lets Sentinel pull those firewall logs directly.
Be respectful. No spam.
Question 2 of 35