sub1という名前のAzureサブスクリプションを作成します。 sub1では、workspace1という名前のLog Analyticsワークスペースを作成します。 Azure Security Center を有効にし、ワークスペース 1 を使用するように Security Center を構成します。 Security Centerが、workspace1にレポートを送信するAzure仮想マシンからのイベントを処理するようにする必要があります。 あなたはどうすべきでしょうか?
正解:A
When configuring Microsoft Defender for Cloud (formerly Azure Security Center) to use a specific Log Analytics workspace, you must ensure the Security solution is installed in that workspace so that security events from VMs reporting to the workspace are processed by Defender for Cloud. Registering a provider, creating workflow automations, or creating a workbook do not enable data processing for recommendations /alerts; installing the solution (now surfaced as the Defender for Cloud agent/solution enablement) does.