Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are deploying a new Ubuntu virtual machine to act as a Syslog/CEF collector for Microsoft Sentinel. After installing the Log Analytics (MMA/OMS) agent by running the onboarding script that you downloaded from the Common Event Format (CEF) data-connector page, you must configure the network security group (NSG) that protects the collector so that it can receive CEF messages from on-premises firewalls. Which inbound rule configuration meets Microsoft's published requirements without further changes to the script or to rsyslog on the collector?
The onboarding script that Sentinel provides for the CEF connector configures rsyslog on the Linux collector to listen for incoming CEF and Syslog traffic on the standard Syslog port 514 for both TCP and UDP. Therefore, the only firewall/NSG change required is to allow inbound traffic on port 514 for the two protocols. Ports 6514, 22, or 25226 are not opened by the script, nor are they used by default for external CEF forwarding; 6514 is the IANA-registered port for Syslog over TLS (not configured by the script), 22 is reserved for SSH management, and 25226 is used internally by the agent, not for external connections.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Syslog/CEF collector?
Open an interactive chat with Bash
Why is port 514 used for CEF and Syslog traffic?
Open an interactive chat with Bash
What does NSG do in the context of the Ubuntu virtual machine?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .