Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 1Objective 3

Ingest Data into the Microsoft Sentinel SIEM and Platform SC-200 Practice Questions (Page 4)

Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
7concepts
40–45%of the exam

Questions 16–20

  1. 16foundation · easy

    When configuring the Windows Security Events via AMA connector in Microsoft Sentinel, what must be created to define which event IDs and log levels to collect?

    Select an answer first
  2. 17application · medium

    Your organization has 2,000 legacy Windows Server 2012 R2 servers that cannot have the Azure Monitor Agent (AMA) installed directly. You need to collect Windows Security events from these servers into Microsoft Sentinel. You have a limited number of Windows Server 2022 collector servers available. What should you configure?

    Select an answer first
  3. 18application · medium

    Your organization uses a custom security application that writes JSON logs to a Linux server. You need to ingest these logs into Microsoft Sentinel for analysis. The logs do not match any built-in connector. What should you do?

    Select an answer first
  4. 19application · medium

    Your environment has 2,000 non-domain-joined Windows servers that must send Security events to Microsoft Sentinel. You have limited bandwidth and want to minimize the number of internet-facing endpoints. You decide to use Windows Event Forwarding (WEF). Which collector configuration should you use?

    Select an answer first
  5. 20application · medium

    Your network devices (routers, switches, firewalls) send logs in syslog format. You need to ingest these logs into Microsoft Sentinel. Some devices support CEF, others only raw syslog. You have a Linux server available. What should you do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.