Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 3
Ingest Data into the Microsoft Sentinel SIEM and Platform SC-200 Practice Questions (Page 1)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
7concepts
40–45%of the exam
Questions 1–5
- 1
Your organization has an Azure subscription with resources in multiple regions. You need to collect Azure activity logs and resource logs into Microsoft Sentinel. You want to use Azure Policy to automate the configuration, but you also need to ensure that logs from all regions are collected. What should you do?
Select an answer first - 2
Your security team has a firewall that sends CEF logs to a Linux VM with the AMA installed. The logs are being ingested into Sentinel, but you notice that some logs are missing. You suspect the DCR is filtering out logs. You need to ensure all CEF logs are collected. What should you do?
Select an answer first - 3
What is the purpose of using Azure Policy in the context of collecting Azure activities into Microsoft Sentinel?
Select an answer first - 4
Your security team has a network appliance that sends logs in Common Event Format (CEF). You need to ingest these logs into Microsoft Sentinel. The appliance can send Syslog to a specific IP address. You have a Linux VM that can reach Sentinel. What should you do?
Select an answer first - 5
Your network has a legacy Unix server that sends logs in Syslog format. You need to ingest these logs into Microsoft Sentinel. The server cannot have any agent installed. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.