sub1 という名前の Azure サブスクリプションを作成します。 sub1 では、workspace1 という名前の Log Analytics ワークスペースを作成します。 Azure Security Center を有効にし、workspace1 を使用するように Security Center を構成します。 Security Center が、workspace1 に報告する Azure 仮想マシンからのイベントを処理することを確認する必要があります。 あなたは何をするべきか?
正解:A
When configuring Microsoft Defender for Cloud (formerly Azure Security Center) to use a specific Log Analytics workspace, you must ensure the Security solution is installed in that workspace so that security events from VMs reporting to the workspace are processed by Defender for Cloud. Registering a provider, creating workflow automations, or creating a workbook do not enable data processing for recommendations /alerts; installing the solution (now surfaced as the Defender for Cloud agent/solution enablement) does.