Microsoft Security Operations Analyst Associate SC-200 Practice Question
You need Microsoft Sentinel to receive detailed Azure Policy compliance and evaluation information from all existing subscriptions in your tenant. What should you do first to ensure that data is ingested into the Log Analytics workspace that Sentinel uses?
Create a diagnostic setting on every subscription that routes the Microsoft.PolicyInsights log categories to the Sentinel workspace.
Deploy the built-in Azure Policy initiative that installs the Azure Policy data connector solution in all workspaces.
Assign the Security Administrator (Security Admin) role to the Log Analytics workspace so it can read policy resources.
Enable a data collection rule in Microsoft Sentinel that targets the subscriptions and selects the Azure Policy data source.
The Azure Policy data connector relies on Azure Monitor diagnostic settings to stream PolicyInsights logs. Until a diagnostic setting is created on each subscription (or managed centrally at the tenant root) that sends the PolicyInsights log categories to the Log Analytics workspace connected to Microsoft Sentinel, no compliance or evaluation data reaches the workspace. Assigning Azure Policy initiatives, adding Sentinel solutions, or enabling data collection rules do not by themselves transmit the logs; they act on data only after it has been forwarded.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Microsoft.PolicyInsights log category and why is it important?
Open an interactive chat with Bash
How do diagnostic settings work in Azure Monitor?
Open an interactive chat with Bash
What is a Log Analytics workspace in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .