exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 16 discussion

Actual exam question from Microsoft's SC-200
Question #: 16
Topic #: 3
[All SC-200 Questions]

You have an Azure Sentinel deployment in the East US Azure region.
You create a Log Analytics workspace named LogsWest in the West US Azure region.
You need to ensure that you can use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to LogsWest.
What should you do first?

  • A. Deploy Azure Data Catalog to the West US Azure region.
  • B. Modify the workspace settings of the existing Azure Sentinel deployment.
  • C. Add Azure Sentinel to a workspace.
  • D. Create a data connector in Azure Sentinel.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Eltooth
Highly Voted 3 years, 7 months ago
Correct answer - C. Cross-workspace queries can now be included in scheduled analytics rules. You can use cross-workspace analytics rules in a central SOC, and across tenants (using Azure Lighthouse) as in the case of an MSSP, subject to the following limitations: * Up to 20 workspaces can be included in a single query. * Azure Sentinel must be deployed on every workspace referenced in the query. * Alerts generated by a cross-workspace analytics rule, and the incidents created from them, exist only in the workspace where the rule was defined. They will not be displayed in any of the other workspaces referenced in the query. https://docs.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants#cross-workspace-workbooks
upvoted 28 times
...
9802f06
Most Recent 1 week, 6 days ago
Selected Answer: D
To ensure that you can use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to the Log Analytics workspace named LogsWest, you should first: D. Create a data connector in Azure Sentinel. Creating a data connector will allow Azure Sentinel to connect to the LogsWest workspace and query the data stored there. This is a necessary step to integrate the workspace with your existing Azure Sentinel deployment and enable the scheduled analytics rules to generate alerts based on the data in LogsWest.
upvoted 1 times
...
xRiot007
5 months ago
Selected Answer: C
Unless you are using a central SOC or Lighthouse, you need to deploy Sentinel on every workspace referenced in the query: https://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants#include-cross-workspace-queries-in-scheduled-analytics-rules
upvoted 1 times
...
g_man_rap
9 months ago
Selected Answer: D
C. Add Azure Sentinel to a workspace. Why this is incorrect: Adding Azure Sentinel to a workspace is the initial step to enable Sentinel capabilities on that particular Log Analytics workspace. However, since the existing deployment is already in the East US region and you need to work with the LogsWest workspace, this option doesn't solve the problem of querying across regions. D. Create a data connector in Azure Sentinel. Why this is correct: To use data from the LogsWest Log Analytics workspace within your Azure Sentinel deployment in the East US, you need to create a data connector in Azure Sentinel. A data connector allows you to ingest data from various sources, including other Log Analytics workspaces, into Azure Sentinel. Once the data connector is set up, Azure Sentinel can generate alerts based on queries to the LogsWest workspace.
upvoted 3 times
...
chepeerick
1 year, 6 months ago
Correct
upvoted 1 times
...
mali1969
1 year, 8 months ago
Selected Answer: D
To use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to LogsWest, you need to first create a data connector in Azure Sentinel. A data connector is a way to connect data sources to Azure Sentinel, so that you can collect and analyze data from various sources such as Azure services, Microsoft 365, or other cloud or on-premises solutions. By creating a data connector, you can enable Azure Sentinel to ingest data from LogsWest and use it for scheduled analytics rules. Therefore, the correct answer is D. Create a data connector in Azure Sentinel
upvoted 1 times
...
donathon
1 year, 9 months ago
Selected Answer: C
https://learn.microsoft.com/en-us/azure/sentinel/quickstart-onboard >> So since you need create the workspace first then logically you should do C first followed by D. So my answer is C.
upvoted 3 times
...
[Removed]
2 years, 2 months ago
Selected Answer: D
To use scheduled analytics rules in an existing Azure Sentinel deployment to generate alerts based on queries to a Log Analytics workspace in a different region, you need to create a data connector in Azure Sentinel. Therefore, the correct answer is: D. Create a data connector in Azure Sentinel.
upvoted 2 times
wsrudmen
2 years, 2 months ago
This account "exmITQS" seems to me a little bit strange. A lot of wrong answer and explanations in different questions. If it's not the intent, I'm really sorry for my message. But other take care to not be confused.
upvoted 10 times
stredovek
2 years, 2 months ago
I dare say that exmITQS posting answers from https://chat.openai.com/
upvoted 7 times
7c0a
1 year, 10 months ago
Indeed, and using ChatGPT for this matter is very unreliable.
upvoted 5 times
...
...
...
...
stromnessian
3 years, 2 months ago
Selected Answer: C
I'm going for C here.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago