Microsoft Security Operations Analyst Associate SC-200 Practice Question

You plan to reduce the number of Azure Monitor Agent (AMA) installations required to ingest Windows Security log events into a Microsoft Sentinel workspace. You decide to use Windows Event Forwarding (WEF) so that only a single Windows Event Collector (WEC) server will run AMA and forwarders will not need the agent.

After you deploy a domain-joined Windows Server as the WEC server and configure the necessary subscriptions, you create a data collection rule (DCR) that targets the WEC server and adds the ForwardedEvents channel as an event log source.

Which destination table will receive the forwarded security events in the Log Analytics workspace, and what must you do if you instead want those events to land in the SecurityEvent table?

  • They will be stored in the Event table; to use SecurityEvent you must forward the events into the WEC server's local Security channel and have the DCR collect from Security instead of ForwardedEvents.

  • They will be rejected unless you enable the CollectSecurityEvents setting in the DCR; after enabling, they go to the SecurityEvent table by default.

  • They will be stored in the SecurityEvent table automatically; no additional configuration is required because AMA detects forwarded security events.

  • They will be written to a new ForwardedSecurityEvent table; you must enable the Sentinel Ingestion mapping feature to redirect them to SecurityEvent.

Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot