SC-200 Exam Question 21

Your company stores the data for every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant.
Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription.
You deploy Azure Sentinel to a new Azure subscription.
You need to perform hunting queries in Azure Sentinel to search across all the Log Analytics workspaces of all the subscriptions.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 22

    You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.
    What should you include in the solution? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 23

    You use Azure Sentinel.
    You need to receive an immediate alert whenever Azure Storage account keys are enumerated.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • SC-200 Exam Question 24

    You manage the security posture of an Azure subscription that contains two virtual machines name vm1 and vm2.
    The secure score in Azure Security Center is shown in the Security Center exhibit. (Click the Security Center tab.)

    Azure Policy assignments are configured as shown in the Policies exhibit. (Click the Policies tab.)

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 25

    You have an Azure Sentinel deployment in the East US Azure region.
    You create a Log Analytics workspace named LogsWest in the West US Azure region.
    You need to ensure that you can use scheduled analytics rules in the existing Azure Sentinel deployment to generate alerts based on queries to LogsWest.
    What should you do first?