nerdexam
Microsoft

SC-300 · Question #69

You have an Azure Active Directory (Azure AD) tenant that uses conditional access policies. You plan to use third-party security information and event management (SIEM) to analyze conditional access…

The correct answer is C. audit logs in JSON format. You can also choose to download the filtered data, up to 250,000 records, by selecting the Download button. You can download the logs in either CSV or JSON format. You can use the JSON transform feature in the Power Query Editor in Excel to split each property in the JSON…

Submitted by kwame.gh· Mar 6, 2026Implement authentication and access management

Question

You have an Azure Active Directory (Azure AD) tenant that uses conditional access policies. You plan to use third-party security information and event management (SIEM) to analyze conditional access usage. You need to download the Azure AD log by using the administrative portal. The log file must contain changes to conditional access policies. What should you export from Azure AD?

Options

  • Aaudit logs in CSV format
  • Bsign-ins in CSV format
  • Caudit logs in JSON format
  • Dsign-ins in JSON format

How the community answered

(54 responses)
  • A
    6% (3)
  • B
    9% (5)
  • C
    81% (44)
  • D
    4% (2)

Explanation

You can also choose to download the filtered data, up to 250,000 records, by selecting the Download button. You can download the logs in either CSV or JSON format. You can use the JSON transform feature in the Power Query Editor in Excel to split each property in the JSON object in the AuditData column into multiple columns so that each property has its https://docs.microsoft.com/en-us/microsoft-365/compliance/export-view-audit-log- records?view=o365-worldwide

Topics

#audit logs#conditional access#SIEM integration#Azure AD logs

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice