exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 6 question 1 discussion

Actual exam question from Microsoft's SC-200
Question #: 1
Topic #: 10
[All SC-200 Questions]

HOTSPOT -
You need to implement Azure Defender to meet the Azure Defender requirements and the business requirements.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ReffG
Highly Voted 2 years, 9 months ago
The provided answer is correct. For reference: https://docs.microsoft.com/en-us/azure/sentinel/connect-windows-security-events?tabs=LAA
upvoted 21 times
Muffen
2 years, 2 months ago
Better reference: https://docs.microsoft.com/en-us/azure/sentinel/windows-security-event-id-reference
upvoted 5 times
Anil0512
8 months, 2 weeks ago
This is perfect thank you.
upvoted 1 times
...
...
...
Discuss4certi
Highly Voted 2 years, 7 months ago
LA1 - as the requirements state that all logs need to be gathered in one workspace. And this one already existed. Common is also correct. following the link referenced by ReffG it is stated for common logs: 'A standard set of events for auditing purposes. A full user audit trail is included in this set.'
upvoted 17 times
...
chepeerick
Most Recent 7 months, 1 week ago
Correct option
upvoted 2 times
...
Xyz_40
1 year, 8 months ago
correct! LA1 Common (Logs collected by Log Analytics must provide a full audit trail of user activities.) And only Common events contains audit trail logs or information
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...