SC-200 · Question #271
You create an Azure subscription named sub1. In sub1, you create a Log Analytics workspace named workspace1. You enable Microsoft Defender for Cloud and configure Defender for Cloud to use…
The correct answer is A. From Defender for Cloud, modify Microsoft Defender for Servers plan settings. Security event log collection from Azure VMs in Defender for Cloud is controlled through the Microsoft Defender for Servers plan settings. Within those settings, you configure the data collection tier (None, Minimal, Common, or All Events) that determines which Windows security…
Question
You create an Azure subscription named sub1. In sub1, you create a Log Analytics workspace named workspace1. You enable Microsoft Defender for Cloud and configure Defender for Cloud to use workspace1. You need to collect security event logs from the Azure virtual machines that report to workspace1. What should you do?
Options
- AFrom Defender for Cloud, modify Microsoft Defender for Servers plan settings.
- BIn sub1, register a provider.
- CFrom Defender for Cloud, create a workflow automation.
- DIn workspace1, create a workbook.
How the community answered
(35 responses)- A80% (28)
- B11% (4)
- C3% (1)
- D6% (2)
Explanation
Security event log collection from Azure VMs in Defender for Cloud is controlled through the Microsoft Defender for Servers plan settings. Within those settings, you configure the data collection tier (None, Minimal, Common, or All Events) that determines which Windows security events are forwarded to the linked Log Analytics workspace. Option B (registering a provider) handles resource provider registration, not log collection. Option C (workflow automation) triggers automated responses to alerts, not log collection. Option D (workbooks) is a visualization feature in Log Analytics, not a data collection configuration.
Topics
Community Discussion
No community discussion yet for this question.