Courseiva
easyMultiple Choice

SC-200 Practice Question: A SOC analyst wants to ingest firewall logs from…

A SOC analyst wants to ingest firewall logs from a Palo Alto Networks appliance into Microsoft Sentinel using the Common Event Format (CEF) connector. The analyst has already set up a Linux syslog forwarder. What is the next required step to complete the data ingestion?

⚠ Common exam trap

Watch out — candidates often confuse the CEF connector's agent installation step with the Azure Monitor Agent (AMA) or think that creating the data connector in the portal alone is sufficient, when in fact the Linux forwarder must first run the CEF installation script to enable log parsing and forwarding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run the installation script provided by the Sentinel CEF connector page on the Linux forwarder.

The CEF connector for Palo Alto Networks in Microsoft Sentinel requires a Linux syslog forwarder to have the CEF agent installed and configured. The installation script provided on the Sentinel CEF connector page automates the setup of the Log Analytics agent (formerly OMS agent) with the correct syslog daemon configuration to parse and forward CEF-formatted logs. Since the forwarder is already deployed, running this script is the immediate next step to enable log ingestion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install the Azure Monitor Agent on the Linux forwarder.

    Why it's wrong here

    Installing the Azure Monitor Agent (AMA) is insufficient because the CEF connector's forwarder is built around the legacy Log Analytics for Linux agent, not AMA. The installation script from the Sentinel CEF connector page explicitly deploys the OMS agent and configures it to accept CEF messages; AMA has no role in parsing CEF into the CommonSecurityLog schema. Without the OMS agent, the forwarder will not be able to run the CEF-specific parsing service or forward events to the Sentinel workspace.

  • ✓

    Run the installation script provided by the Sentinel CEF connector page on the Linux forwarder.

    Why this is correct

    Running the script from the Sentinel CEF connector page is the correct action — it performs an end-to-end setup on the Linux forwarder by installing and connecting the Log Analytics agent, configuring rsyslog or syslog-ng to listen for CEF over TCP, and deploying the CEF parser that maps incoming events to the CommonSecurityLog table. The script also starts the required services and opens the appropriate firewall ports, turning the Linux box into a dedicated CEF forwarder for Palo Alto and other appliances.

  • ✗

    Create a Syslog data connector in Sentinel and specify the Palo Alto facility.

    Why it's wrong here

    A generic Syslog connector does not produce the CommonSecurityLog schema that CEF-based detections and analytics rules expect. The Syslog connector collects standard RFC 3164/5424 logs into the Syslog table in raw form, whereas the CEF connector's forwarder script transforms the CEF header and extension into normalized, queryable fields. Simply specifying 'Palo Alto' as a facility in a Syslog connector will not invoke the CEF parsing required for the sentinel content pack to function.

  • ✗

    Enable Azure Arc on the firewall appliance.

    Why it's wrong here

    Enabling Azure Arc on the firewall appliance is a management-plane operation that makes the device visible in Azure Resource Manager and allows Azure services like Policy or Defender for Cloud, but it does not install a log-collection agent nor does it provide a channel for Syslog/CEF events to reach Sentinel. The Palo Alto firewall is a network appliance that lacks the ability to run the Log Analytics agent, and Arc does not bridge that gap; you still need a separate Linux forwarder to ingest its logs.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.