nerdexam
Microsoft

SC-300 · Question #69

You have an Azure Active Directory (Azure AD) tenant that uses conditional access policies. You plan to use third-party security information and event management (SIEM) to analyze conditional access u

Sign in or unlock SC-300 to reveal the answer and full explanation for question #69. The question stem and answer options stay visible for context.

Submitted by kwame.gh· Mar 6, 2026Implement authentication and access management

Question

You have an Azure Active Directory (Azure AD) tenant that uses conditional access policies. You plan to use third-party security information and event management (SIEM) to analyze conditional access usage. You need to download the Azure AD log by using the administrative portal. The log file must contain changes to conditional access policies. What should you export from Azure AD?

Options

  • Aaudit logs in CSV format
  • Bsign-ins in CSV format
  • Caudit logs in JSON format
  • Dsign-ins in JSON format

Unlock SC-300 to see the answer

You've previewed enough free SC-300 questions. Unlock SC-300 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#audit logs#conditional access#SIEM integration#Azure AD logs
Full SC-300 Practice