nerdexam
Microsoft

SC-200 · Question #268

You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server. You need to configure Defender for Cloud to collect event data from…

The correct answer is A. Configure auto-provisioning by setting the security event storage to Common. E. From Defender for Cloud in the Azure portal, enable Microsoft Defender for Servers. To collect event data from VMs with minimal effort and cost, two steps are needed. First (E), enable Microsoft Defender for Servers in Defender for Cloud - this is the prerequisite plan that unlocks VM-level security data collection. Second (A), configure auto-provisioning with…

Submitted by zhang_li· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Cloud

Question

You have an Azure subscription that uses Microsoft Defender for Cloud and contains 100 virtual machines that run Windows Server. You need to configure Defender for Cloud to collect event data from the virtual machines. The solution must minimize administrative effort and costs. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AConfigure auto-provisioning by setting the security event storage to Common.
  • BFrom the Microsoft Endpoint Manager admin center, enable automatic enrollment.
  • CFrom the Azure portal, create an Azure Event Grid subscription.
  • DConfigure auto-provisioning by setting the security event storage to All Events.
  • EFrom Defender for Cloud in the Azure portal, enable Microsoft Defender for Servers.

How the community answered

(64 responses)
  • A
    72% (46)
  • B
    6% (4)
  • C
    19% (12)
  • D
    3% (2)

Explanation

To collect event data from VMs with minimal effort and cost, two steps are needed. First (E), enable Microsoft Defender for Servers in Defender for Cloud - this is the prerequisite plan that unlocks VM-level security data collection. Second (A), configure auto-provisioning with the 'Common' security event storage setting, which collects the most operationally valuable events without the cost and noise of 'All Events' (D). Option B (Endpoint Manager enrollment) is for Intune device management, not Defender for Cloud. Option C (Event Grid) is an event routing service unrelated to this use case. 'All Events' (D) increases cost unnecessarily compared to 'Common.'

Topics

#Microsoft Defender for Cloud#Security Event Collection#Auto-provisioning#Microsoft Defender for Servers

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice