Microsoft Related Exams
SC-200 Exam
The Microsoft SC-200 exam assesses your knowledge in various security operation domains, including:
CertsTopics offers high-quality SC-200 exam dumps, questions and answers, and practice tests tailored to the Microsoft Certified: Security Operations Analyst Associate Exam syllabus. Our SC-200 study materials come in PDF and testing engine formats, ensuring effective preparation and a high success rate.
You need to implement Azure Sentinel queries for Contoso and Fabrikam to meet the technical requirements.
What should you include in the solution? To answer, select the appropriate options in the answer area .
NOTE: Each correct selection is worth one point.

You have an on-premises Linux server that runs a background process named App1 and has the Azure Connected Machine agent installed.
You have a Microsoft Sentinel workspace named WS1.
You need to configure a data collection rule (DCR) named DCR1 that will use the Syslog via AMA connector to collect messages related to App1. The solution must meet the following requirements:
• Only collect messages that have a priority level of critical.
• Minimize the volume of data collected.
Which facility and log level should you configure for DCR1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to create the test rule to meet the Azure Sentinel requirements. What should you do when you create the rule?