SC-100 Practice Question 3930
Exam: SC-100
Domain: Design security operations, identity, and compliance capabilities
Difficulty: hard
An organization needs to collect syslog and CEF logs from 50 on-premises perimeter firewalls into Microsoft Sentinel. What architecture should you design for scalable on-premises ingestion?
Answer Options
A
Clustered Linux Log Forwarders with AMA and Syslog daemons behind a load balancer
B
Connecting 50 USB cables directly into Azure servers
C
Streaming logs over cleartext HTTP port 80 to public IPs
D
Typing firewall event messages manually into Sentinel
Correct Answer
A: Clustered Linux Log Forwarders with AMA and Syslog daemons behind a load balancer
Explanation
Deploy a clustered pool of dedicated Linux Log Forwarders with Azure Monitor Agent (AMA) and Syslog daemons behind a network load balancer, streaming CEF data to Sentinel over TLS.