exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 2 question 42 discussion

Actual exam question from Microsoft's SC-200
Question #: 42
Topic #: 2
[All SC-200 Questions]

You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server.

You need to configure Defender for Cloud to collect event data from the virtual machines. The solution must minimize administrative effort and costs.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

  • A. From the workspace created by Defender for Cloud, set the data collection level to Common.
  • B. From the Microsoft Endpoint Manager admin center, enable automatic enrollment.
  • C. From the Azure portal, create an Azure Event Grid subscription.
  • D. From the workspace created by Defender for Cloud, set the data collection level to All Events.
  • E. From Defender for Cloud in the Azure portal, enable automatic provisioning for the virtual machines.
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
teouba
Highly Voted 2 years ago
Selected Answer: AE
Answer is correct. Microsoft Endpoint Manager (Intune) has nothing to do with configuring Defender for Cloud to collect data from VMs Plus it would need a lot of administrative effort also to make relevant Intune configurations. All you need to do is enable auto-provisioning from Defender for Cloud. There you ll be asked if you want to store security events and in what level (none, minimal, common, all). Since there are only 2 options provided here (common & all) we go with the least effort so A -> common You can check the below video at 04:14 https://www.youtube.com/watch?v=Ufk65R7UJCc
upvoted 21 times
kabooze
1 year, 6 months ago
You go for "common" for the least costs, not the effort :) (being pedantic here, i know)
upvoted 3 times
...
Ramye
1 year, 2 months ago
Note: Auto-Provisioning page has been renamed to Settings & monitoring in Microsoft Defender for Cloud Microsoft Defender for Cloud --> Environment settings --> Azure Subscription --> Defender plans --> Settings & monitoring
upvoted 2 times
...
...
[Removed]
Highly Voted 2 years, 2 months ago
Selected Answer: BE
B. From the Microsoft Endpoint Manager admin center, enable automatic enrollment: This will automatically enroll all Windows devices, including the virtual machines in your subscription, in Microsoft Endpoint Manager, which will then allow Defender for Cloud to collect event data from these devices. To enable automatic enrollment, you can follow the steps in the Microsoft documentation. E. From Defender for Cloud in the Azure portal, enable automatic provisioning for the virtual machines: This will automatically configure the virtual machines to send event data to Defender for Cloud without the need for manual configuration or agent installation. To enable automatic provisioning, you can follow the steps in the Azure Defender documentation.
upvoted 7 times
Holii
2 years ago
Intune is for Device Management for onboarding company/BYOD devices and not relevant here. Goal is the least administrative effort possible with least cost. We would at least need a Data Connector to fulfill lower costs. This would be AE.
upvoted 7 times
...
...
aks_exam
Most Recent 1 year ago
on exam 2024/April
upvoted 2 times
...
kazaki
1 year, 2 months ago
Selected Answer: AE
Simple A and E Don’t even think
upvoted 1 times
...
a95f6f1
1 year, 5 months ago
AE for me too!
upvoted 1 times
...
im20batman
1 year, 5 months ago
Selected Answer: BE
not correct BE
upvoted 1 times
Hawklx
10 months, 2 weeks ago
Microsoft Endpoint Manager is not Defender for Cloud
upvoted 1 times
...
...
chepeerick
1 year, 6 months ago
check this
upvoted 1 times
...
donathon
1 year, 8 months ago
Selected Answer: AE
AE for me
upvoted 1 times
...
EricShon
1 year, 8 months ago
Selected Answer: AE
E. From Defender for Cloud in the Azure portal, enable automatic provisioning for the virtual machines. Automatic provisioning allows Microsoft Defender for Cloud to automatically deploy the Log Analytics agent to Azure VMs, which will then forward the event data to a Log Analytics workspace. This reduces the administrative effort as you won't have to manually install and configure the agent on each VM. A. From the workspace created by Defender for Cloud, set the data collection level to Common. Setting the data collection level to "Common" minimizes costs because it means only essential security-related events will be collected. The "All Events" setting (Option D) would result in higher costs because more data would be stored in the workspace, but it might not be necessary for security monitoring.
upvoted 3 times
...
tatendazw
1 year, 10 months ago
In MS Defnder for Cloud environment settings Defender plans there you enabled auto provision with LAA/MMA turned on and configure Security events storage to Common https://learn.microsoft.com/en-us/azure/defender-for-cloud/auto-deploy-azure-monitoring-agent#deploy-the-azure-monitor-agent-with-defender-for-cloud
upvoted 1 times
tatendazw
1 year, 10 months ago
LAA/MMA = Log Analytics agent/Azure Monitor agent
upvoted 1 times
...
...
D_PaW
1 year, 11 months ago
Selected Answer: AE
Endpoint Manager is for "Endpoints" only ie. Windows 10/11, Android, iOS and Mac. NOT Server or Defender for Cloud related. So must be AE https://learn.microsoft.com/en-us/azure/defender-for-cloud/working-with-log-analytics-agent#what-event-types-are-stored-for-common-and-minimal
upvoted 2 times
...
Elpintintun
1 year, 11 months ago
AE B is not possible because Microsot Endpoint Manager doesnt enroll servers and it says: contains 100 virtual machines that run windows server.
upvoted 3 times
ccurio
1 year, 10 months ago
https://techcommunity.microsoft.com/t5/intune-customer-success/windows-server-devices-now-recognized-as-a-new-os-in-intune/ba-p/3767773
upvoted 1 times
...
...
default_wizard
2 years ago
Selected Answer: AE
Agree, A/E are correct
upvoted 4 times
...
haskelatchi
2 years ago
Selected Answer: AE
The answer is not B, enrolling windows devices has no direct impact on configuring defender for cloud to collect event data from virtual machines
upvoted 3 times
...
evilprime
2 years, 1 month ago
seems correct to me, A and E.
upvoted 1 times
...
antoniokt
2 years, 2 months ago
Selected Answer: BE
Correct is BE
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago