Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are deploying Microsoft Sentinel to monitor Azure Active Directory (Azure AD) sign-in and audit events. You want to bring in the required data and automatically deploy the associated analytic rules, workbooks, hunting queries, and playbooks in a single step. In addition, you must ensure that any future version of this content is applied to your workspace without manual intervention. Which action should you perform in the Microsoft Sentinel portal to meet these requirements?
Install the Azure Active Directory solution from the Content hub and configure the solution to update automatically.
Import the Azure AD workbook from the Workbook gallery and enable the matching analytics rule templates.
Configure Azure AD diagnostic settings to stream logs to an Event Hub that Microsoft Sentinel already monitors.
Enable the Azure Active Directory data connector and manually turn on sign-in and audit log collection.
Installing the Azure Active Directory solution from Microsoft Sentinel's Content hub adds the data connector together with its related analytic rules, workbooks, hunting queries, and playbooks in one operation. After the solution is installed, you can set its update mode to Automatic so that any new version published in the Content hub is deployed to the workspace without further administrator action.
Enabling the Azure AD data connector alone brings in the logs but does not deliver or automatically maintain the associated content. Importing individual workbooks or enabling rules one by one also lacks automatic version updates. Forwarding logs through Event Hub or other collection methods similarly does not package or auto-update the additional Sentinel content.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Microsoft Sentinel Content hub?
Open an interactive chat with Bash
How does setting the update mode to 'Automatic' benefit the solution?
Open an interactive chat with Bash
What is the difference between a data connector and a solution in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .