Microsoft Security Operations Analyst Associate SC-200 Practice Question

You manage a Microsoft Sentinel workspace. You want to ingest JSON-formatted telemetry from a line-of-business applications by using the Azure Monitor Logs Ingestion API. The data must be stored in a new custom log table named AppEvents_CL within the workspace. Before you can send events to the ingestion endpoint, which Azure resource must you create to satisfy a required prerequisite?

  • A syslog forwarder configured with the Log Analytics agent

  • A diagnostic setting that routes the application events to the custom table

  • A workbook template that defines the schema of the AppEvents_CL table

  • A data collection endpoint (DCE) that your data collection rule will reference

Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot