AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization wants to use Microsoft Sentinel to detect and respond to threats. You need to ensure that Sentinel can ingest data from Azure Firewall logs. Which three components are required? (Choose three.)
⚠ Common exam trap
Many candidates assume the Log Analytics agent is required for all Azure resources, but Azure Firewall (and other PaaS services) use diagnostic settings instead, making Option D a common distractor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable diagnostic logs on Azure Firewall.
Azure Firewall logs must be enabled via diagnostic settings to send data to a Log Analytics workspace. Without diagnostic logs, the firewall does not produce the necessary log data for Sentinel to ingest. This is the foundational step for log collection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable diagnostic logs on Azure Firewall.
Why this is correct
Azure Firewall does not emit its logs to Sentinel by default. Instead, you must enable diagnostic settings on the firewall resource itself, selecting the relevant log categories (e.g., AzureFirewallNetworkRule, AzureFirewallApplicationRule, AzureFirewallDnsProxy) and streaming them to a Log Analytics workspace. This is the foundational ingestion step that makes firewall data available to Sentinel; without it, no traffic analysis or detection can occur.
- ✓
A Log Analytics workspace.
Why this is correct
A Log Analytics workspace is the mandatory destination for the diagnostic log stream that Azure Firewall emits. Sentinel is built on top of this workspace, and all Sentinel tables, analytics rules, and workbooks rely on logs being physically stored there. The diagnostic settings configure the workspace as the sink, so if no workspace exists (or the stream isn't pointed to one), the firewall logs are either discarded or sent elsewhere, and Sentinel has no data to ingest.
- ✗
Assign an Azure Policy to enforce diagnostic logs on all firewalls.
Why it's wrong here
Using Azure Policy to enforce diagnostic logs across all firewalls is an optional governance mechanism, not a technical prerequisite for Sentinel detection. While a policy (such as one that deploys diagnostic settings automatically) can help ensure consistent log collection at scale, Sentinel's ingestion works exactly the same regardless of whether the settings were applied manually or via policy. The policy only automates the same diagnostic-settings configuration; it does not introduce any new capability or data path to Sentinel.
- ✗
Install the Log Analytics agent on the Azure Firewall.
Why it's wrong here
The Log Analytics agent (and the newer Azure Monitor Agent) is not applicable to Azure Firewall because it is a fully managed platform-as-a-service. There is no underlying virtual machine on which to install an agent; the agent is designed for guest OS logs and metrics from IaaS VMs. Azure Firewall's diagnostic logs are instead emitted through the Azure Monitor resource-level diagnostic settings, bypassing the need for any agent deployment entirely.
- ✓
The Azure Firewall data connector in Sentinel.
Why this is correct
The Azure Firewall data connector in Sentinel is the integration component that imports the already-collected firewall logs into Sentinel's workspace tables (e.g., AzureDiagnostics) and maps them to a schema that KQL queries and analytics rules can use. However, this connector is downstream of the diagnostic settings pipeline; it cannot capture logs that have not been streamed to the workspace first. The connector is necessary for translating the raw workspace logs into Sentinel-ready data, but it is one link in a chain.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.