Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security engineer is designing a Microsoft Sentinel deployment for a hybrid environment. The organization requires all on-premises Windows server security events to be ingested into Sentinel. Due to network segmentation, these servers cannot directly access the internet. Which component should the engineer deploy to facilitate the ingestion of these logs?
- AAzure Security Center
- BAzure Monitor Agent (AMA)
- CLog Analytics Gateway
- DAzure Activity Data Connector
Show answer & explanationAnswer & explanation
Correct answer: C. Log Analytics Gateway
The Log Analytics Gateway acts as a proxy for agents (like AMA) that cannot directly connect to Azure Monitor or Log Analytics. It collects logs from multiple on-premises sources and forwards them securely to Sentinel, addressing network segmentation constraints.
Why the other options are wrong
- A. Azure Security Center (now Defender for Cloud) is a cloud security posture management solution, not a log ingestion proxy for segmented on-premises networks.
- B. While AMA is used to collect logs from Windows servers, it still needs connectivity to Azure. The Gateway provides this connectivity when direct access is blocked.
- D. Azure Activity Data Connector ingests Azure control plane activities, not on-premises server logs.
Log Analytics Gateway
The Log Analytics Gateway is an HTTP forward proxy that enables agents (like AMA) on machines without direct internet access to send log data to Azure Monitor and Microsoft Sentinel.
- Acts as a proxy for agents.
- Used in segmented or air-gapped on-premises environments.
- Collects data from multiple sources and forwards it securely.
Memory trick: Bridge the on-prem gap with a Gateway to the cloud.