Microsoft Security Operations Analyst Associate SC-200 Practice Question
You deploy an Azure Linux virtual machine as a log collector for Microsoft Sentinel. After installing the Log Analytics agent, you run the Microsoft-provided cef_installer.py script by using all default settings. You then configure several on-premises firewalls to forward Common Event Format (CEF) messages over TCP to the collector. To which destination port on the collector should the firewalls send their CEF messages so that the events will be ingested by Microsoft Sentinel?
When you execute the cef_installer.py script with its default parameters, the script configures rsyslog on the collector to listen externally on TCP (and UDP) port 514. It also adds an IPTables rule that forwards any traffic received on port 514 to the Log Analytics agent's local listener on port 25226. Because of this configuration, all external devices must be configured to send their CEF-formatted Syslog messages to port 514 on the collector. Traffic sent to ports 25224, 25226, or 6514 will not be accepted from remote sources unless you override the script's defaults.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Common Event Format (CEF)?
Open an interactive chat with Bash
What is the role of the Log Analytics agent in Microsoft Sentinel?
Open an interactive chat with Bash
How does the cef_installer.py script configure rsyslog and IPTables?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .