Microsoft Security Operations Analyst Associate SC-200 Practice Question
You manage a Microsoft Sentinel workspace connected to several Azure subscriptions. Security analysts need to investigate how frequently Audit and Deny policies are triggered and to correlate those results with security alerts already stored in the workspace. You must start ingesting Azure Policy compliance data into Microsoft Sentinel without deploying any additional agents or custom scripts and with the least administrative effort. What should you do?
Create a diagnostic setting for each subscription that streams the Policy category to the Log Analytics workspace and then enable the Azure Activity data connector.
Enable the Azure Resource Graph connector and schedule a query that exports PolicyInsights data to a custom table in the workspace.
Deploy the Log Analytics agent to all Azure virtual machines and configure the Change Tracking solution to collect Policy snapshots.
Enable the Azure Policy (Preview) data connector in the Microsoft Sentinel portal and select the Azure subscriptions whose compliance data you want to stream.
Microsoft Sentinel includes a built-in "Azure Policy" data connector that relies on Azure diagnostic settings rather than on the Log Analytics agent. Enabling this connector automatically creates or updates a diagnostic setting named "send-to-sentinel" in each selected subscription and starts streaming policy compliance records (PolicyInsights) to the workspace. Using the Azure Activity connector alone will not capture detailed compliance evaluation results, and creating custom data collection rules or assigning extra roles is unnecessary for this scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Azure Policy (Preview) data connector?
Open an interactive chat with Bash
How does the Azure Policy data connector differ from the Azure Activity connector?
Open an interactive chat with Bash
What is PolicyInsights data?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .