Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your on-premises network contains 400 Windows Server 2022 machines that you want to monitor in Microsoft Sentinel. Only Security event IDs 4720 and 4726 must be collected, and you must not open any inbound firewall ports on the servers. You will use Azure Monitor Agent and data collection rules (DCRs). Which solution meets the requirements?
Stream Windows security events to an Azure Event Hub and connect Sentinel by using the Event Hub data connector.
Configure a source-initiated Windows Event Forwarding subscription to a dedicated collector, install Azure Monitor Agent on the collector, and create a DCR that filters event IDs 4720 and 4726 from the ForwardedEvents channel.
Install Azure Monitor Agent on each server and create a DCR that collects the full Security log.
Configure a collector-initiated Windows Event Forwarding subscription, install the legacy Microsoft Monitoring Agent on the collector, and enable the Security Events via Legacy Agent data connector.
A source-initiated Windows Event Forwarding (WEF) subscription causes each server to push the selected Security events to a designated collector over outbound WinRM, so no inbound ports need to be opened on the source computers. Installing Azure Monitor Agent on the event collector lets the collector send the ForwardedEvents channel to the Log Analytics workspace. A DCR applied to the collector can filter the forwarded log so that only event IDs 4720 and 4726 are sent to Microsoft Sentinel, reducing ingestion costs. Installing the agent on every server or using the legacy MMA connector would not avoid inbound ports or allow the same centralized filtering. Streaming through Event Hubs meets neither the firewall nor the cost-reduction requirement without additional infrastructure.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Windows Event Forwarding (WEF)?
Open an interactive chat with Bash
What is Azure Monitor Agent (AMA) and how does it differ from the Legacy Microsoft Monitoring Agent (MMA)?
Open an interactive chat with Bash
What are data collection rules (DCRs) in Azure Monitor Agent?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .