SC-200 · Question #443
SC-200 Question #443: Real Exam Question with Answer & Explanation
Sign in or unlock SC-200 to reveal the answer and full explanation for question #443. The question stem and answer options stay visible for context.
Question
You have an on-premises virtual machine named VM1 that runs Windows Server. You have a Microsoft Sentinel workspace named Workspace1. You install the Azure Connected Machine agent on VM1. You need to collect events from VM1 and send the events to Workspace1. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct answer is worth one point.
Options
- AOnVM1, install the Microsoft Monitoring Agent.
- BOn VM1, install the Log Analytics agent.
- CFrom the Microsoft Defender portal, add the Windows Security Events via AMA data connector.
- DFrom the Microsoft Defender portal, add the Syslog via AMA data connector.
- EOn VM1, enable the Azure Monitor Agent extensions.
- FFrom the Microsoft Defender portal, create a data collection rule (DCR) that targets VM1.
Unlock SC-200 to see the answer
You've previewed enough free SC-200 questions. Unlock SC-200 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.