Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-200 Exam - Topic 3 Question 28 Discussion

You have a third-party security information and event management (SIEM) solution.You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign-events in near real time.What should you do to route events to the SIEM solution?
B) Configure the Diagnostics settings in Azure AD to stream to an event hub.
A) Create an Azure Sentinel workspace that has a Security Events connector.
C) Create an Azure Sentinel workspace that has an Azure Active Directory connector.
D) Configure the Diagnostics settings in Azure AD to archive to a storage account.

Microsoft SC-200 Exam - Topic 3 Question 28 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 28
Topic #: 3
[All SC-200 Questions]

You have a third-party security information and event management (SIEM) solution.

You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign-events in near real time.

What should you do to route events to the SIEM solution?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

0/2000 characters
Wilbert
8 months ago
I’m not so sure about C, isn’t it just for monitoring?
upvoted 0 times
...
Cheryl
9 months ago
Totally agree with B, it’s the most efficient method!
upvoted 0 times
...
Owen
9 months ago
Wait, can you really get near real-time with option D? Seems off.
upvoted 0 times
...
Marshall
9 months ago
I think A is better for security events specifically.
upvoted 0 times
...
Pearlene
9 months ago
Option B is the way to go for real-time alerts!
upvoted 0 times
...
Emilio
9 months ago
I remember that archiving to a storage account wouldn't help with real-time alerts, so I think that option can be ruled out right away.
upvoted 0 times
...
Elenora
9 months ago
I’m a bit confused between the Azure Sentinel workspace options. I thought both connectors could work, but I can't recall which one is specifically for Azure AD sign-in events.
upvoted 0 times
...
Temeka
9 months ago
I practiced a similar question where we had to set up alerts for Azure AD, and I feel like the event hub option was the right choice for real-time alerts.
upvoted 0 times
...
Lottie
9 months ago
I think I remember something about using Azure AD diagnostics settings to stream events, but I'm not sure if it's to an event hub or something else.
upvoted 0 times
...
Youlanda
9 months ago
I'm pretty confident about this one. I think the key is understanding the core principles of SDN, like the separation of control and data planes. Option B looks like the correct answer to me.
upvoted 0 times
...
Alpha
9 months ago
Hmm, this seems like a tricky one. I'll need to carefully consider the different leadership styles and how they relate to the description provided.
upvoted 0 times
...
Vanda
9 months ago
I think it's similar to the practice question we did on hedging with swaptions. You want to limit losses while taking advantage of potential gains, right?
upvoted 0 times
...
Audry
9 months ago
I'm not entirely sure, but I feel like poor password management was also mentioned a lot in our studies.
upvoted 0 times
...
Floyd
9 months ago
I'm a little confused by this question. There seem to be a lot of options, and I'm not sure which two are the correct steps. I'll have to read through it again carefully and try to eliminate the wrong answers.
upvoted 0 times
...

Save Cancel