ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 119 - SC-200 discussion

Report
Export

You have a third-party security information and event management (SIEM) solution.

You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign-events in near real time.

What should you do to route events to the SIEM solution?

A.

Create an Azure Sentinel workspace that has a Security Events connector.

Answers
A.

Create an Azure Sentinel workspace that has a Security Events connector.

B.

Configure the Diagnostics settings in Azure AD to stream to an event hub.

Answers
B.

Configure the Diagnostics settings in Azure AD to stream to an event hub.

C.

Create an Azure Sentinel workspace that has an Azure Active Directory connector.

Answers
C.

Create an Azure Sentinel workspace that has an Azure Active Directory connector.

D.

Configure the Diagnostics settings in Azure AD to archive to a storage account.

Answers
D.

Configure the Diagnostics settings in Azure AD to archive to a storage account.

Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/overview-monitoring

asked 05/10/2024
Luis Campoy
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first