Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You onboard Server1 to Microsoft Defender for Endpoint. Does this meet the goal?
Onboarding Server1 to Microsoft Defender for Endpoint enables endpoint detection and response telemetry, threat protection, and security recommendations for that specific device, but Defender for Endpoint is a separate security product from Microsoft Sentinel and does not configure Server1 as a log source for the Windows Firewall data connector. Onboarding to Defender for Endpoint installs its own sensor and forwards its own telemetry to the Microsoft 365 Defender portal and, when connected, to Sentinel through the Defender for Endpoint connector, but it does not deploy the Azure Monitor Agent or the data collection rule that the Windows Firewall connector specifically depends on to collect Windows Firewall event log entries from Server1. Because these are two independent data pipelines with different underlying agents and different data collection rules, onboarding Server1 to Defender for Endpoint has no effect on whether Windows Firewall logs specifically reach Sentinel through the Windows Firewall connector, so this solution does not meet the stated goal.
Currently there are no comments in this discussion, be the first to comment!