Microsoft Certified:Security Operations Analyst Associate
Domain 1Objective 3
Ingest Data into the Microsoft Sentinel SIEM and Platform SC-200 Practice Questions (Page 3)
Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
7concepts
40–45%of the exam
Questions 11–15
- 11
Your organization has a mix of Windows servers: some are modern and support AMA, but a significant number are legacy Windows Server 2008 R2 that do not support AMA. You need to collect Windows Security events from all servers into Microsoft Sentinel. You want to minimize the number of agents and forwarding infrastructure. What should you do?
Select an answer first - 12
In a Windows Event Forwarding (WEF) configuration, what is the role of the Windows Event Collector (WEC) server?
Select an answer first - 13
Which Microsoft Sentinel data connector is designed to ingest Common Event Format (CEF) logs from security appliances such as firewalls and intrusion detection systems?
Select an answer first - 14
Your threat intelligence team has a large number of indicators in a proprietary format. You need to ingest them into Microsoft Sentinel. You have a system that can convert them to STIX JSON. You want to automate the ingestion process. What should you do?
Select an answer first - 15
Which of the following is a valid method to ingest data into a custom log table in Microsoft Sentinel?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.