QuestionQ35

Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your company’s Azure subscription contains 100 virtual machines with Azure Diagnostics enabled.

You need to analyze the security events from a Windows Server 2016 virtual machine and have already opened Azure Monitor.

Which of the following options should you use?

Explanation

Azure Monitor Logs is the query interface for collected Windows security-event records, such as those in the SecurityEvent table. Metrics are numerical measurements, while the Activity Log records Azure resource-management operations rather than guest operating system security events.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!