nerdexam
Microsoft

SC-200 · Question #99

You have a third-party security information and event management (SIEM) solution. You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign-events in…

The correct answer is B. Configure the Diagnostics settings in Azure AD to stream to an event hub. Routing logs to an Azure event hub allows you to integrate with third-party SIEM tools like Sumologic and Splunk. https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/tutorial-azure-monitor- stream-logs-to-event-hub

Submitted by haruto_sh· Apr 18, 2026Manage a security operations environment

Question

You have a third-party security information and event management (SIEM) solution. You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign-events in near real time. What should you do to route events to the SIEM solution?

Options

  • ACreate an Azure Sentinel workspace that has a Security Events connector.
  • BConfigure the Diagnostics settings in Azure AD to stream to an event hub.
  • CCreate an Azure Sentinel workspace that has an Azure Active Directory connector.
  • DConfigure the Diagnostics settings in Azure AD to archive to a storage account.

How the community answered

(41 responses)
  • A
    7% (3)
  • B
    73% (30)
  • C
    17% (7)
  • D
    2% (1)

Explanation

Routing logs to an Azure event hub allows you to integrate with third-party SIEM tools like Sumologic and Splunk. https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/tutorial-azure-monitor- stream-logs-to-event-hub

Topics

#Azure AD Logs#Diagnostics Settings#Event Hubs#SIEM Integration

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice