exam questions

Exam AZ-900 All Questions

View all questions & answers for the AZ-900 exam

Exam AZ-900 topic 1 question 223 discussion

Actual exam question from Microsoft's AZ-900
Question #: 223
Topic #: 1
[All AZ-900 Questions]

HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/azure/sentinel/overview

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
wendyy
Highly Voted 3 years, 7 months ago
I think the first should be NO. Azure Sentinel use Log Analytics workspace to stored log. After 90 days if Sentinel is enabled. Then you can export of logs from your Log Analytics workspace to destinations such as Azure Storage and Event Hub.
upvoted 35 times
wendyy
3 years, 7 months ago
More for this: Log Analytics workspace will keep your log inforatmion, after 90 days, you need pay money per G/month. If you want to use your storage account to store log, you need pay money to export log into your storage account or Event Hub. So first one is NO. storage account is only one option you can transfer log if you don't want pay money to keep. Log Analytics workspace is correct place.
upvoted 5 times
...
Fosnefes
2 years, 2 months ago
By default, logs ingested into Microsoft Sentinel are stored in Azure Monitor Log Analytics. See - https://learn.microsoft.com/en-us/azure/sentinel/store-logs-in-azure-data-explorer?tabs=adx-event-hub
upvoted 1 times
...
...
VincentvdS
Highly Voted 3 years, 7 months ago
Sentinel Stores your events in a Log Analytics workspace and can retrieve events from a starage location. it doesnt store the events in a storage location.
upvoted 11 times
...
Zakirh
Most Recent 5 months ago
No, Azure Sentinel does not store collected events directly in an Azure Storage account. Instead, it uses Log Analytics workspaces to store and analyze data collected from various sources. So for the first one the answer should be NO
upvoted 1 times
...
e3ddceb
9 months, 2 weeks ago
No. Azure Sentinel stores collected events in Azure Log Analytics workspaces, not in an Azure Storage account. Yes. Azure Sentinel can remediate incidents automatically using Playbooks, which are collections of procedures that can be run from Azure Sentinel. Yes. Azure Sentinel can collect Windows Defender firewall logs from Azure VMs.
upvoted 4 times
...
siculoct
10 months, 3 weeks ago
N,Y,Y is corrrect
upvoted 2 times
...
Pcservices
11 months, 3 weeks ago
N,Y,Y is the correct answer
upvoted 1 times
...
xqzit
1 year, 3 months ago
YYY https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/azure-storage-account Azure Storage account is a cloud solution for modern data storage scenarios. It contains all your data objects: blobs, files, queues, tables, and disks. This connector lets you stream Azure Storage accounts diagnostics logs into your Microsoft Sentinel workspace, allowing you to continuously monitor activity in all your instances, and detect malicious activity in your organization. For more information, see the
upvoted 1 times
...
Wablo
1 year, 6 months ago
Hi guys, please check the below link for clarity, I will go with NYY. As you plan your Microsoft Sentinel deployment, you typically want to understand its pricing and billing models to optimize your costs. Microsoft Sentinel's security analytics data is stored in an Azure Monitor Log Analytics workspace. Billing is based on the volume of data analyzed in Microsoft Sentinel and stored in the Log Analytics workspace. https://learn.microsoft.com/en-us/azure/sentinel/billing?tabs=simplified%2Ccommitment-tiers
upvoted 2 times
...
Rajivjain
1 year, 10 months ago
YYY : Yes, Azure Sentinel can store collected events in an Azure Storage account. Azure Sentinel is a cloud-native security information and event management (SIEM) solution provided by Microsoft. It enables organizations to collect, analyze, and respond to security events and incidents across their environment. Azure Sentinel can ingest data from various sources, including logs and events from Azure services, on-premises infrastructure, and third-party systems. The collected events can be stored in an Azure Storage account, which provides a scalable and durable storage solution for the data. This allows organizations to retain and analyze security event data over a longer period of time, as required by their compliance or investigative needs.
upvoted 3 times
...
Ciupaz
2 years, 1 month ago
Microsoft Sentinel security analytics data is stored in an Azure Monitor Log Analytics workspace. Billing is based on the volume of that data in Microsoft Sentinel and the Azure Monitor Log Analytics workspace storage.
upvoted 3 times
...
mmatchev
2 years, 2 months ago
No, Azure Sentinel does not store collected events in an Azure Storage account. Azure Sentinel stores events in a centralized Log Analytics workspace. The Log Analytics workspace acts as the data repository for Azure Sentinel and provides a single place for storing, analyzing, and querying security-related data from various sources.
upvoted 2 times
...
Contactfornitish
3 years, 1 month ago
First answer is incorrect. As pointed out by others, Sentinel doesn't store content in storage account but in Log Analytics. Can say for sure since completed SC-200 few weeks back and SC-900 with 1000/1000 and one of the question was similar
upvoted 9 times
...
PreethiP
3 years, 2 months ago
NYY - Stores events in Log Analytics workspace
upvoted 1 times
...
atilla
3 years, 3 months ago
now called Microsoft Sentinel
upvoted 2 times
...
peymani
3 years, 4 months ago
https://azure.microsoft.com/en-us/pricing/details/azure-sentinel/ Microsoft Sentinel provides intelligent security analytics across your enterprise. The data for this analysis is stored in an Azure Monitor Log Analytics workspace. Microsoft Sentinel is billed based on the volume of data ingested for analysis in Microsoft Sentinel and stored in the Azure Monitor Log Analytics workspace. Microsoft Sentinel offers a flexible and predictable pricing model. There are two ways to pay for the Microsoft Sentinel service: Capacity Reservations and Pay-As-You-Go. Q1: NO
upvoted 4 times
...
mufflon
3 years, 4 months ago
By default, logs ingested into Microsoft Sentinel are stored in Azure Monitor Log Analytics, So Q1 is NO
upvoted 2 times
...
swapnasantoshi
3 years, 4 months ago
what is the ans for Q1?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago