Microsoft Security Operations Analyst Associate SC-200 Practice Question

You are deploying Microsoft Sentinel to monitor Azure Active Directory (Azure AD) sign-in and audit events. You want to bring in the required data and automatically deploy the associated analytic rules, workbooks, hunting queries, and playbooks in a single step. In addition, you must ensure that any future version of this content is applied to your workspace without manual intervention. Which action should you perform in the Microsoft Sentinel portal to meet these requirements?

  • Import the Azure AD workbook from the Workbook gallery and enable the matching analytics rule templates.

  • Configure Azure AD diagnostic settings to stream logs to an Event Hub that Microsoft Sentinel already monitors.

  • Install the Azure Active Directory solution from the Content hub and configure the solution to update automatically.

  • Enable the Azure Active Directory data connector and manually turn on sign-in and audit log collection.

Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot