SC-100 Practice Question 3930

Exam: SC-100
Domain: Design security operations, identity, and compliance capabilities
Difficulty: hard
An organization needs to collect syslog and CEF logs from 50 on-premises perimeter firewalls into Microsoft Sentinel. What architecture should you design for scalable on-premises ingestion?

Answer Options

A
Clustered Linux Log Forwarders with AMA and Syslog daemons behind a load balancer
B
Connecting 50 USB cables directly into Azure servers
C
Streaming logs over cleartext HTTP port 80 to public IPs
D
Typing firewall event messages manually into Sentinel

Correct Answer

A: Clustered Linux Log Forwarders with AMA and Syslog daemons behind a load balancer

Explanation

Deploy a clustered pool of dedicated Linux Log Forwarders with Azure Monitor Agent (AMA) and Syslog daemons behind a network load balancer, streaming CEF data to Sentinel over TLS.