Which components configure a Defender for Cloud Apps log collector?

Answer Correct answer: B, E — configure the data source and the host IP address or FQDN when adding a log collector for automatic syslog upload in Defender for Cloud Apps.

You have a Microsoft 365 E5 subscription. You plan to ingest syslog data from a supported firewall device to Microsoft Defender for Cloud Apps. You need to configure automatic log upload. Which two components should you configure for the log collector? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  1. the receiver type
  2. the data source Correct Answer
  3. the username and password
  4. a connection string
  5. the host IP address or FQDN Correct Answer

Community Votes

BE
56%
AB
44%

56% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests whether you can distinguish log collector settings from data source settings; the trap is choosing the receiver type, which is configured on the Data sources tab, not on the log collector itself.

Automatic syslog upload to Microsoft Defender for Cloud Apps requires a log collector and an associated data source. This page confirms the two log collector components are the data source and the host IP address or FQDN (B and E).

Choosing A (receiver type) and B (data source) is tempting because receiver type is part of automatic log upload, but it belongs to the data source definition, not the log collector record.

Community Discussion (8 comments)

Ody 👍 10
The Answer is correct: B and E The two components are Data sources and Log collectors. Under Log collectors you configure: Name Host IP address or FQDN Data source(s)
Xive 👍 5 Selected: BE
BE is correct. https://learn.microsoft.com/en-us/defender-cloud-apps/discovery-docker-windows
fabiomartinsnet 👍 2 Selected: BE
Wen you go to secure score it has steps of implementation: 1) Add Data Source (B) 2) Add Log Collector (providing address) (E)
SummerK 👍 1 Selected: BE
The correct answers are: B. the data source E. the host IP address or FQDN Explanation: To configure automatic log upload for syslog data from a supported firewall device to Microsoft Defender for Cloud Apps, you need to set up a log collector. The key components required for this configuration are: The data source: You need to specify the data source as the source from which logs are being collected. This would typically be the syslog server or the firewall device that is sending logs to Microsoft Defender for Cloud Apps. The host IP address or FQDN: This is the IP address or Fully Qualified Domain Name (FQDN) of the log collector or the syslog server. It’s necessary for Defender for Cloud Apps to know where to receive the logs from.
Endi99 👍 1 Selected: BE
The answer is B and E
justITtopics 👍 4 Selected: AB
https://learn.microsoft.com/en-us/defender-cloud-apps/discovery-docker-windows 1.In the Microsoft Defender portal, select Settings > Cloud Apps > Cloud Discovery > Automatic log upload > Data sources tab. 2e. Set the Receiver type to either FTP, FTPS, Syslog – UDP, or Syslog – TCP, or Syslog – TLS. Extra: Supported Firewalls and proxies: https://learn.microsoft.com/en-us/defender-cloud-apps/set-up-cloud-discovery At the bottom: Configure automatic log upload for continuous reports -> https://learn.microsoft.com/en-us/defender-cloud-apps/discovery-docker (Docker in Onpremise Windows, Podman, Docker in Azure or Docker in Azure Kubernetes)
665d390 👍 1 Selected: AB
You have a Microsoft 365 E5 subscription. You plan to ingest syslog data from a supported firewall device to Microsoft Defender for Cloud Apps. You need to configure automatic log upload. Which two components should you configure for the log collector? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point. A. the receiver type B. the data source C. the username and password D. a connection string E. the host IP address or FQDN To set up automatic log upload for the log collector, you should configure: A. the receiver type B. the data source These configurations will enable the log collector to properly handle the syslog data from your firewall device
HelloItsSam 👍 2 Selected: AB
A. the receiver type – You need to specify the type of log receiver (such as syslog) that will be used to collect the logs from the firewall device. B. the data source – This refers to the firewall or other network device that is providing the syslog data, and it needs to be properly configured to send the logs to the log collector.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender for Cloud Apps automatic log upload separates configuration into data sources and log collectors. When you add a log collector under Cloud Discovery > Automatic log upload > Log collectors, you supply its name, host IP address or FQDN, and the data source(s) it will serve. Therefore B (the data source) and E (the host IP address or FQDN) are the components configured for the log collector. The receiver type is selected when defining the data source, so it is not part of the log collector record. Community explanations such as Ody's note that "The two components are Data sources and Log collectors" align with this portal workflow.

Why the Other Options Are Wrong

A (receiver type) is configured on the Data sources tab, not on the log collector; you choose FTP, FTPS, Syslog UDP, Syslog TCP, or Syslog TLS there. C (username and password) is not a standard log collector component in this flow; authentication for the collector is handled by the collector deployment or registration, not asked here. D (a connection string) is not used for Cloud Discovery automatic log upload; log collectors register to the service and forward logs, not via a connection string. Some learners picked AB because the receiver type is needed somewhere in automatic log upload, but the question narrows the scope to the log collector.

Community Comment Notes

Ody explained the split clearly: data sources and log collectors are separate, and log collectors contain the host IP/FQDN and data source association. fabiomartinsnet described Secure Score implementation steps as "Add Data Source" then "Add Log Collector" providing an address, supporting B and E. justITtopics pointed to the data source tab for receiver type, which is precisely why A is not a log collector component. SummerK also selected BE, while the AB voters generally conflated the overall automatic upload prerequisites with the log collector-specific fields.

Official Reference

Exam Strategy

When a question asks what to configure for the log collector, separate the collector record from the data source record. In the portal, receiver type lives on the Data sources tab, while host IP/FQDN and data source association live on the Log collectors tab; pick B and E.

Frequently Asked Questions

Why is the receiver type not configured on the log collector?

The receiver type (FTP, FTPS, Syslog UDP/TCP/TLS) is part of the data source definition on the Data sources tab, while the log collector record stores its name, host IP/FQDN, and associated data source(s).

Do I still need to configure a receiver type for syslog upload?

Yes, but you configure it when creating the data source, not when creating the log collector; the question asks specifically about log collector components.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide