nerdexam
Microsoft

SC-200 · Question #185

You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server. You need to configure Defender for Cloud to collect event data from…

The correct answer is B. From the Microsoft Endpoint Manager admin center, enable automatic enrollment: This will E. From Defender for Cloud in the Azure portal, enable automatic provisioning for the virtual. To collect event data from 100 Windows Server VMs with minimal administrative effort and cost, two actions are required: (E) Enable automatic provisioning in Defender for Cloud, which automatically deploys the Log Analytics agent to every VM in the subscription without…

Submitted by yuki_2020· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Cloud

Question

You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server. You need to configure Defender for Cloud to collect event data from the virtual machines. The solution must minimize administrative effort and costs. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AFrom the workspace created by Defender for Cloud, set the data collection level to Common.
  • BFrom the Microsoft Endpoint Manager admin center, enable automatic enrollment: This will
  • CFrom the Azure portal, create an Azure Event Grid subscription.
  • DFrom the workspace created by Defender for Cloud, set the data collection level to All Events.
  • EFrom Defender for Cloud in the Azure portal, enable automatic provisioning for the virtual

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    72% (21)
  • C
    17% (5)
  • D
    7% (2)

Explanation

To collect event data from 100 Windows Server VMs with minimal administrative effort and cost, two actions are required: (E) Enable automatic provisioning in Defender for Cloud, which automatically deploys the Log Analytics agent to every VM in the subscription without requiring manual installation on each machine-this is the primary cost- and effort-saving mechanism. (B) Enable automatic enrollment in Microsoft Endpoint Manager, which ensures devices are properly onboarded into the management plane, enabling Defender for Endpoint integration. Setting data collection to 'All Events' (D) would increase Log Analytics ingestion costs unnecessarily; 'Common' (A) is a more cost-efficient level but is not sufficient alone. Creating an Event Grid subscription (C) is unrelated to this use case.

Topics

#Microsoft Defender for Cloud#Data Collection#Azure Virtual Machines#Security Event Logs

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice