Microsoft Security Operations Analyst Associate SC-200 Practice Question
You plan to collect Windows Security log events from several on-premises Windows Server 2022 computers and ingest them into Microsoft Sentinel. You will deploy the Azure Monitor Agent (AMA) to the servers and create a data collection rule (DCR) that targets only the Security channel. After the DCR starts sending data, to which Log Analytics table in the Microsoft Sentinel workspace will the events be written by default?
When Windows Security log data is collected by the Azure Monitor Agent and routed to Microsoft Sentinel through a data collection rule, the records are stored in the SecurityEvent table of the Log Analytics workspace. The WindowsEvent table is used for non-security Windows event channels via AMA, the legacy Event table is used by the older Log Analytics (MMA) agent, and CommonSecurityLog is reserved for CEF-formatted data from network and security devices.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Azure Monitor Agent (AMA)?
Open an interactive chat with Bash
What is a Data Collection Rule (DCR)?
Open an interactive chat with Bash
What is the difference between the SecurityEvent and WindowsEvent tables in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .