AZ-801 — Frequently Asked Questions

Community-vetted answers to 10 common questions about this exam.

The primary method is to install the Log Analytics agent (also known as the Microsoft Monitoring Agent or MMA) on the on-premises virtual machines. This agent is configured to connect to a Log Analytics workspace that is linked to your Azure Sentinel instance. Once connected, the agent collects security event logs (such as Windows Event Logs or Syslog) and forwards them to the workspace, where Azure Sentinel can ingest, analyze, and generate alerts based on the data.

Selecting the 'Prevent failback' option means that if a clustered role (application or service) fails over from a preferred owner node to another node, it will not automatically move back to the preferred node when it comes back online. The role will remain on the current node until a manual failover is initiated or another failure occurs. This is useful for preventing service disruption during the restart of a preferred node after maintenance.

The first prerequisite is to ensure that a Network Security Group (NSG) is associated with the network interface or subnet of the virtual machine. Just-in-Time access works by dynamically creating and removing NSG rules to allow traffic on specific ports for a limited time. Without an NSG in place, the JIT feature cannot control inbound access to the VM.

Yes, they can be used together. The Azure Arc agent is used to connect the on-premises or multi-cloud server to Azure, making it a manageable Azure resource. Once the server is Arc-enabled, you can deploy the Azure Monitor Agent (AMA) extension to it. The AMA is then configured with a Data Collection Rule (DCR) to collect specific logs, such as Windows Firewall logs, and send them to a Log Analytics workspace connected to Microsoft Sentinel.

The user account should be a member of the Account Operators built-in group. Members of this group have the necessary permissions to create, delete, and manage domain user and computer accounts, which includes promoting a server to a domain controller. This provides the necessary permissions without granting the full, unrestricted control that comes with membership in the Domain Admins or Enterprise Admins groups.

You can enable Microsoft Defender for Servers within the Microsoft Defender for Cloud service in the Azure portal. Specifically, you navigate to 'Environment settings', select the relevant subscription or management group, and then go to the 'Defender plans' blade. From there, you can toggle the plan for 'Servers' on to enable the enhanced security features for all current and future servers in that scope.

Any server that can run the Log Analytics agent (MMA) or the Azure Monitor Agent (AMA) and connect to a Log Analytics workspace can send Windows Firewall logs to Microsoft Sentinel. This includes Azure virtual machines, on-premises servers, and virtual machines hosted in other clouds (like AWS or GCP), provided they have network connectivity to the Log Analytics workspace service endpoints.

The process involves installing the Log Analytics agent (MMA) on the on-premises Windows Server and configuring it to report to a Log Analytics workspace that is being monitored by Microsoft Defender for Cloud. Once the agent is connected and reporting, Defender for Cloud will automatically detect the server, assess its security posture, and apply the relevant policies and recommendations, effectively onboarding it into the Defender for Cloud dashboard.

The recommended method is to use Windows Admin Center. After connecting to the hyper-converged cluster, you can navigate to the 'Storage Spaces Direct' section. The dashboard provides a clear, graphical overview of the storage pools, including total capacity, available capacity, and health status. Alternatively, you can use the Get-StoragePool PowerShell cmdlet on any node in the cluster to retrieve this information.

The administrator should use the Serial Console feature in the Azure portal. The Serial Console provides direct text-based access to the VM's command-line interface, independent of the guest OS's network configuration. This allows an administrator to troubleshoot and fix network stack issues, such as misconfigured IP addresses or firewall rules, even when all network connectivity to the VM is lost.

← Back to Microsoft AZ-801 Exam Questions & Knowledge Points Guide