nerdexam
Microsoft

SC-200 · Question #271

You create an Azure subscription named sub1. In sub1, you create a Log Analytics workspace named workspace1. You enable Microsoft Defender for Cloud and configure Defender for Cloud to use…

The correct answer is A. From Defender for Cloud, modify Microsoft Defender for Servers plan settings. Security event log collection from Azure VMs in Defender for Cloud is controlled through the Microsoft Defender for Servers plan settings. Within those settings, you configure the data collection tier (None, Minimal, Common, or All Events) that determines which Windows security…

Submitted by viktor_hu· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Cloud

Question

You create an Azure subscription named sub1. In sub1, you create a Log Analytics workspace named workspace1. You enable Microsoft Defender for Cloud and configure Defender for Cloud to use workspace1. You need to collect security event logs from the Azure virtual machines that report to workspace1. What should you do?

Options

  • AFrom Defender for Cloud, modify Microsoft Defender for Servers plan settings.
  • BIn sub1, register a provider.
  • CFrom Defender for Cloud, create a workflow automation.
  • DIn workspace1, create a workbook.

How the community answered

(35 responses)
  • A
    80% (28)
  • B
    11% (4)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Security event log collection from Azure VMs in Defender for Cloud is controlled through the Microsoft Defender for Servers plan settings. Within those settings, you configure the data collection tier (None, Minimal, Common, or All Events) that determines which Windows security events are forwarded to the linked Log Analytics workspace. Option B (registering a provider) handles resource provider registration, not log collection. Option C (workflow automation) triggers automated responses to alerts, not log collection. Option D (workbooks) is a visualization feature in Log Analytics, not a data collection configuration.

Topics

#Microsoft Defender for Cloud#Log Analytics#Security Event Collection#Microsoft Defender for Servers

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice