exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 66 discussion

Actual exam question from Microsoft's SC-200
Question #: 66
Topic #: 3
[All SC-200 Questions]

HOTSPOT
-

Your on-premises network contains 100 servers that run Windows Server.

You have an Azure subscription that uses Microsoft Sentinel.

You need to upload custom logs from the on-premises servers to Microsoft Sentinel.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jwkin
Highly Voted 1 year, 8 months ago
Correct https://learn.microsoft.com/en-us/azure/sentinel/connect-custom-logs?tabs=DCG
upvoted 10 times
789sv
1 year, 4 months ago
https://learn.microsoft.com/en-us/azure/sentinel/data-connectors-reference
upvoted 1 times
...
...
7c0a
Highly Voted 1 year, 4 months ago
This is certainly outdated question, now we would use ARC + AMA + DCR + DCE and a custom tables. https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-collection-text-log?tabs=portal If we stick to the legacy solution, answers are Log analytics agent - can be installed different ways, no need of ARC as mentioned in previous comments Data Connectors page of Sentinel - configure custom logs https://learn.microsoft.com/en-us/azure/sentinel/connect-custom-logs?tabs=DCG
upvoted 8 times
Ramye
8 months, 1 week ago
LAA is still available, though it says will be retired. In the question they might just replace the LAA with AMA (Azure Monitor agent)
upvoted 3 times
...
kabooze
12 months ago
indeed. Wonder if this question will be on the exam as it's old methodology with LAA being deprecated in August 2024
upvoted 1 times
Ramye
8 months, 1 week ago
LAA is still available, though it says will be retired. In the question they might just replace the LAA with AMA (Azure Monitor agent)
upvoted 1 times
...
...
...
chepeerick
Most Recent 12 months ago
Correct option
upvoted 1 times
...
donathon
1 year, 2 months ago
Answer is correct.
upvoted 1 times
donathon
1 year, 1 month ago
The Azure Connected Machine agent enables you to manage your Windows and Linux machines hosted outside of Azure on your corporate network or other cloud providers. >> Apologies, I choose ARC Agent instead because this is on-prem.
upvoted 2 times
...
...
sinslam
1 year, 4 months ago
The servers are hosted on-premises, so for starters, you will require Azure Arc to connect and ingest data to Sentinel. Arc works best with Azure Connected Machine Agent. https://learn.microsoft.com/en-us/azure/azure-arc/servers/agent-overview
upvoted 1 times
kabooze
12 months ago
arc IS the Azure connected machine agent
upvoted 1 times
...
Ramye
8 months ago
the keyword here is custom log - see here - https://learn.microsoft.com/en-us/azure/sentinel/connect-custom-logs?tabs=DCG
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago