Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization must ingest JSON events from a proprietary security appliance into Microsoft Sentinel. The device can send HTTPS POST requests, so you decide to use the Azure Monitor HTTP Data Collector API with the Log-Type header set to SecurityAppliance. Before the appliance starts sending data, what action must you take in the Log Analytics workspace to ensure that events land in the SecurityAppliance_CL table and are queryable?
Manually add SecurityAppliance_CL and define its columns in the Tables blade before any data is sent.
Install the Azure Monitor agent on the appliance and associate it with a data collection rule targeting SecurityAppliance_CL.
No preparation is required; the first successful POST automatically creates the SecurityAppliance_CL table with an inferred schema.
Create an analytics rule in Microsoft Sentinel that references SecurityAppliance_CL; the table is created when the rule is saved.
The Data Collector API automatically creates a custom log table the first time it receives data that uses a previously unseen Log-Type value. Therefore, you do not need to pre-create SecurityAppliance_CL, deploy an agent, or configure analytics rules. Once the first POST succeeds, the table is created and populated, and its columns are inferred from the JSON properties.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does the Azure Monitor HTTP Data Collector API infer the schema of the custom log table?
Open an interactive chat with Bash
What is the purpose of the Log-Type header in the HTTPS POST request?
Open an interactive chat with Bash
What are the benefits of using the Data Collector API for ingesting security-related data?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .