Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Security Operations Analyst Associate

Domain 1Objective 3

Ingest Data into the Microsoft Sentinel SIEM and Platform SC-200 Practice Questions (Page 6)

Part of the Manage a security operations environment domain, which accounts for 40–45% of the SC-200 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~16–29 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
7concepts
40–45%of the exam

Questions 26–30

  1. 26application · medium

    Your security team needs to ingest logs from multiple sources: Windows Security events, Linux syslog, and Azure Activity logs. You want to use the most appropriate connectors for each source. What should you do?

    Select an answer first
  2. 27expert · hard

    Your organization has a security appliance that sends logs in CEF format. You have a Linux server that runs AMA and is already collecting syslog from other devices. You need to ingest the CEF logs into Sentinel. The appliance does not support sending to a different port. What should you do?

    Select an answer first
  3. 28application · medium

    Your organization has a new Azure subscription with 50 virtual machines. You need to collect Azure activity logs (e.g., VM create, delete, and security policy changes) into Microsoft Sentinel. You want to use Azure Policy to ensure that all current and future VMs have diagnostic settings enabled. What should you do?

    Select an answer first
  4. 29application · medium

    Your company has 500 Windows servers that must send Security events (4624, 4625, 4720) to Microsoft Sentinel. The security team wants to use the existing Azure Monitor Agent (AMA) infrastructure and avoid deploying additional forwarding servers. You need to configure collection with the least administrative overhead while ensuring the events are stored in a custom table for long-term retention. What should you do?

    Select an answer first
  5. 30application · medium

    Your company has a mix of Windows and Linux servers. You need to collect Windows Security events and Linux Syslog into Microsoft Sentinel. You want to use a single agent type where possible. What should you do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-200” is a trademark of its owner, used for identification only.