Microsoft SC-200 Sentinel Data Connectors Windows Security Events AMA And WEF Practice Test

 

Skills 1.3 • 35 original questions

This Microsoft SC-200 Security Operations Analyst practice test focuses on sentinel data connectors windows security events ama and wef through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a detection-engineering sprint at Woodgrove Bank, the Defender administrator must choose the correct Sentinel connector for the specified log source and event requirements. Which action most directly satisfies the requirement for the remote-user fleet, response wave 1? The design priority is to separate collection from detection logic.

  1. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  2. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  3. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  4. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: A

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 2

Blue Yonder Airlines is revising its SOC runbook after a audit investigation. Analysts need to collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which implementation should the incident responder select for the production subscription, response wave 1 while trying to preserve investigation context?

  1. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  4. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  5. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability

Correct answer: B

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 3

A ticket escalated to the security operations analyst at Trey Research states one non-negotiable goal: centralize selected Windows events through Windows Event Forwarding before security ingestion. Which choice is the strongest fit for the research subscription, response wave 1? The team also wants to minimize manual analyst steps.

  1. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  2. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  3. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  4. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  5. Select the Microsoft Sentinel data connector that matches the source type and required event stream

Correct answer: B

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 4

For the Tier 1 queue, response wave 2 at Contoso Health, a lateral-movement investigation can proceed only if the team can choose the correct Sentinel connector for the specified log source and event requirements. What should the Defender administrator configure first if the operational goal is to minimize manual analyst steps?

  1. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  2. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  3. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  4. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  5. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query

Correct answer: A

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 5

The security architecture review at Litware Manufacturing focuses on this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which Microsoft security action is most appropriate for the Tier 2 queue, response wave 2, given the need to retain evidence for follow-up analysis?

  1. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  4. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  5. Configure Windows Security Events via AMA and the required data collection rule

Correct answer: E

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 6

A change advisory board at Woodgrove Bank asks how to centralize selected Windows events through Windows Event Forwarding before security ingestion during a multi-cloud monitoring rollout. Which proposed action should the security operations analyst approve for the identity-response team, response wave 2? The change should avoid unnecessary alert noise.

  1. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  2. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  3. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  4. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  5. Review and apply relevant Microsoft Sentinel SOC optimization recommendations

Correct answer: C

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 7

Fourth Coffee has ruled out a manual one-off workaround. For the cloud-security team, response wave 3, the remaining requirement is to choose the correct Sentinel connector for the specified log source and event requirements. Which choice best addresses it and helps avoid unnecessary alert noise?

  1. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  2. Create a custom log table in the Log Analytics workspace for the ingested custom data
  3. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Select the Microsoft Sentinel data connector that matches the source type and required event stream

Correct answer: E

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 8

During post-incident review at A. Datum, the incident responder identifies a gap: the SOC still needs to collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which action should be added for the messaging-security team, response wave 3 before the next incident, with an emphasis on trying to preserve least privilege?

  1. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  2. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  3. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  4. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace
  5. Configure Windows Security Events via AMA and the required data collection rule

Correct answer: E

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 9

The security operations analyst at Contoso Health is comparing several Microsoft security options for a phishing investigation. Which one directly enables the team to centralize selected Windows events through Windows Event Forwarding before security ingestion for the night shift, response wave 3 while helping reduce mean time to respond?

  1. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  2. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  3. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  4. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  5. Configure Defender for Endpoint device groups with the required permissions and automation level

Correct answer: D

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 10

A security-operations workshop at Adventure Works defines the desired outcome as follows: choose the correct Sentinel connector for the specified log source and event requirements. Which implementation should be chosen for the Americas SOC, response wave 4? The team wants to reduce mean time to respond.

  1. Configure the appropriate email notification rule in Microsoft Defender XDR
  2. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  3. Create a custom log table in the Log Analytics workspace for the ingested custom data
  4. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  5. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace

Correct answer: D

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 11

Which Microsoft security action best matches this technical purpose for the high-value-assets group, response wave 4: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. The SOC is trying to scope the change to the affected security domain.

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Create a custom log table in the Log Analytics workspace for the ingested custom data
  4. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  5. Select the Microsoft Sentinel data connector that matches the source type and required event stream

Correct answer: B

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 12

An analyst at Fourth Coffee describes the needed capability this way: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. Which option should be associated with that requirement for the privileged-users group, response wave 4 while the team tries to keep the workflow auditable?

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  3. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  4. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  5. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal

Correct answer: D

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 13

During a design validation for the remote-user fleet, response wave 5, Wingtip Toys documents the following behavior: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. Which Microsoft security feature or action is being described? The objective is to keep the workflow auditable.

  1. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  2. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  3. Configure the appropriate email notification rule in Microsoft Defender XDR
  4. Configure Defender for Endpoint device groups with the required permissions and automation level
  5. Select the Microsoft Sentinel data connector that matches the source type and required event stream

Correct answer: E

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 14

The incident responder must identify the Microsoft security capability that provides this function for the production subscription, response wave 5: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. Which choice is correct if the SOC also needs to avoid changing an unrelated control plane?

  1. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  4. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  5. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing

Correct answer: B

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 15

A runbook for the research subscription, response wave 5 contains this description: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. Which implementation belongs in that runbook during a lateral-movement investigation? The process should improve detection coverage.

  1. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions
  2. Configure the appropriate email notification rule in Microsoft Defender XDR
  3. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  4. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  5. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Correct answer: E

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 16

Alpine Ski House is troubleshooting a SOC tuning initiative. Evidence shows that the decisive requirement is to choose the correct Sentinel connector for the specified log source and event requirements. Which action should the Defender administrator investigate first for the Tier 1 queue, response wave 6, without losing the ability to improve detection coverage?

  1. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  2. Configure Defender for Endpoint device groups with the required permissions and automation level
  3. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed
  4. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  5. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Correct answer: D

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 17

After eliminating network and licensing causes, the incident responder at Wide World Importers determines that success depends on the ability to collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which security action should be checked next for the Tier 2 queue, response wave 6? The team must support repeatable response.

  1. Configure Windows Security Events via AMA and the required data collection rule
  2. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  3. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  4. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal
  5. Configure the appropriate email notification rule in Microsoft Defender XDR

Correct answer: A

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 18

A service-desk escalation during a identity compromise review has been narrowed to one security-operations requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion. Which configuration is the most relevant starting point for the identity-response team, response wave 6 if the SOC wants to separate collection from detection logic?

  1. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  2. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  3. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled
  4. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  5. Configure the appropriate email notification rule in Microsoft Defender XDR

Correct answer: B

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 19

The failure pattern at Northwind Traders affects the cloud-security team, response wave 7. Before making unrelated policy changes, the Defender administrator needs a solution that will choose the correct Sentinel connector for the specified log source and event requirements. Which action is most directly relevant and helps separate collection from detection logic?

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  3. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  4. Create a custom log table in the Log Analytics workspace for the ingested custom data
  5. Configure or tune Microsoft Sentinel anomaly detection for the behavior that should be modeled

Correct answer: B

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Sentinel anomaly detections identify statistically or behaviorally unusual activity that may not be captured by fixed-threshold rules. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 20

While investigating a ransomware response, Tailspin Toys confirms the environment must collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which Microsoft security capability should be validated for the messaging-security team, response wave 7? The investigation should preserve investigation context.

  1. Configure Windows Security Events via AMA and the required data collection rule
  2. Configure the Syslog via AMA or CEF via AMA connector that matches the device log format
  3. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  4. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks
  5. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel

Correct answer: A

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: Syslog and CEF sources require the corresponding AMA-based connector so network and security appliance events are normalized and forwarded into the Sentinel workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 21

Two teams at Alpine Ski House propose different approaches for the night shift, response wave 7. The selection criterion is simple: the chosen approach must centralize selected Windows events through Windows Event Forwarding before security ingestion. Which option should win the technical comparison if the SOC also wants to minimize manual analyst steps?

  1. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  2. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  3. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  4. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  5. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Correct answer: E

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 22

For the Americas SOC, response wave 8, Trey Research wants the least indirect solution to this goal: choose the correct Sentinel connector for the specified log source and event requirements. Which action aligns most closely with that requirement and the need to minimize manual analyst steps?

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  3. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  4. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  5. Tune the Defender XDR alert behavior, including suppression or correlation settings, for the identified signal

Correct answer: C

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Defender XDR alert tuning is used to reduce unwanted alerts and improve how related security signals are surfaced and correlated for investigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 23

A modernization plan at Lucerne Publishing includes a post-incident review. The incident responder is asked to choose the control that specifically helps the organization collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which choice fits best for the high-value-assets group, response wave 8 while supporting the goal to retain evidence for follow-up analysis?

  1. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  4. Use the MITRE ATT&CK mapping to identify which adversary tactics and techniques are covered or missing
  5. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view

Correct answer: B

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: MITRE ATT&CK mapping provides a common adversary-technique framework for evaluating detection coverage and identifying gaps in the SOC detection portfolio. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 24

The privileged-users group, response wave 8 is moving into a controlled rollout at Northwind Traders. Which action should be included when the stated security objective is to centralize selected Windows events through Windows Event Forwarding before security ingestion? The operational standard is to avoid unnecessary alert noise.

  1. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  2. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  3. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  4. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  5. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow

Correct answer: D

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 25

Woodgrove Bank is replacing an ad hoc process during a detection-engineering sprint. The replacement must reliably choose the correct Sentinel connector for the specified log source and event requirements. Which security-operations approach should the Defender administrator implement for the remote-user fleet, response wave 9 if the team also wants to avoid unnecessary alert noise?

  1. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  2. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  3. Configure Windows Security Events via AMA and the required data collection rule
  4. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  5. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action

Correct answer: B

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 26

An audit finding for the production subscription, response wave 9 says the current process does not consistently collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which Microsoft security action most directly closes that gap while helping the SOC preserve least privilege?

  1. Configure Windows Security Events via AMA and the required data collection rule
  2. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  3. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  4. Create a Microsoft Defender XDR custom detection rule from the validated Advanced Hunting query
  5. Select the Microsoft Sentinel data connector that matches the source type and required event stream

Correct answer: A

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Custom detections operationalize an Advanced Hunting query so matching events can generate alerts and trigger response actions on a schedule. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 27

The security operations analyst at Trey Research needs a repeatable configuration for the research subscription, response wave 9. It must centralize selected Windows events through Windows Event Forwarding before security ingestion. Which choice should be implemented instead of relying on manual incident work if the goal is to reduce mean time to respond?

  1. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  2. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  3. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  4. Create a custom log table in the Log Analytics workspace for the ingested custom data
  5. Select the Microsoft Sentinel data connector that matches the source type and required event stream

Correct answer: C

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 28

During readiness testing at Contoso Health, the Tier 1 queue, response wave 10 fails a business requirement because analysts cannot yet choose the correct Sentinel connector for the specified log source and event requirements. Which action should be implemented before rollout continues? The SOC also needs to reduce mean time to respond.

  1. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  2. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  3. Review and apply relevant Microsoft Sentinel SOC optimization recommendations
  4. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  5. Configure Windows Security Events via AMA and the required data collection rule

Correct answer: A

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 29

A governance review asks the incident responder to justify the control selected for the Tier 2 queue, response wave 10. The requirement is to collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which action has the clearest technical alignment while supporting the goal to scope the change to the affected security domain?

  1. Configure Windows Security Events via AMA and the required data collection rule
  2. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  3. Configure the appropriate table or tier retention setting for the required investigation and cost objective
  4. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  5. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR

Correct answer: A

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Retention settings determine how long security data remains available in the relevant Analytics, Data Lake, or XDR tier and should match query, compliance, and cost requirements. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 30

For a multi-cloud monitoring rollout, Woodgrove Bank needs a Microsoft security capability with this effect: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. Which option most accurately provides that capability for the identity-response team, response wave 10? The process should keep the workflow auditable.

  1. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Configure the automated investigation and response capability and its remediation behavior in Microsoft Defender XDR
  4. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  5. Enable and validate automatic attack disruption in Microsoft Defender XDR for eligible attacks

Correct answer: D

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Automated investigation and response can investigate supported alerts and take or recommend remediation actions, reducing manual triage for eligible incidents. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Automatic attack disruption uses correlated XDR signals to contain eligible active attacks across affected identities and devices while the investigation continues. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 31

The operational standard for the cloud-security team, response wave 11 is being rewritten. Which action should be documented when the standard requires analysts to choose the correct Sentinel connector for the specified log source and event requirements and the SOC wants to keep the workflow auditable?

  1. Deploy the required endpoint security policy, including the appropriate attack surface reduction rule configuration
  2. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  3. Configure Windows Security Events via AMA and the required data collection rule
  4. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  5. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view

Correct answer: B

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Endpoint security policy and ASR rules reduce attack surface on managed endpoints and are the direct control for blocking or auditing the targeted risky behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 32

  1. Datum is creating a response playbook for the messaging-security team, response wave 11. Which Microsoft security step belongs in the playbook when the objective is to collect the required Windows Security events with Azure Monitor Agent and a data collection rule? The playbook should also help avoid changing an unrelated control plane.
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Create a Microsoft Sentinel automation rule that matches the incident conditions and performs the required incident action
  4. Configure the appropriate email notification rule in Microsoft Defender XDR
  5. Create or configure a Microsoft Sentinel workbook for the required visualization and operational view
  6. Use Azure Policy and resource diagnostic settings to route the required Azure activity or resource logs to the Sentinel-connected workspace

Correct answer: A

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: Sentinel automation rules evaluate incidents and can automatically update, assign, tag, close, or trigger response workflows when their conditions are met. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Defender XDR notification settings can send email for supported incident, action, and threat-analytics events so analysts receive the requested operational signal. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: Sentinel workbooks provide interactive visualizations over security data and are the appropriate choice for reusable dashboards and analyst views. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Azure Policy can deploy or enforce diagnostic settings at scale so Azure resource and activity telemetry is consistently sent to the target monitoring workspace. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Question 33

During a phishing investigation at Contoso Health, the security operations analyst must centralize selected Windows events through Windows Event Forwarding before security ingestion. Which action most directly satisfies the requirement for the night shift, response wave 11? The design priority is to improve detection coverage.

  1. Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path
  2. Configure Windows Security Events via AMA and the required data collection rule
  3. Enable or configure the required Microsoft Defender for Endpoint advanced feature in the Defender portal
  4. Configure the supported threat-intelligence ingestion path so the required indicators are available in Microsoft Sentinel
  5. Configure the relevant Microsoft Defender for Endpoint rule setting for the endpoint behavior being managed

Correct answer: A

Why: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Option review:

A: Windows Event Forwarding centralizes selected Windows events through collector subscriptions and is appropriate when the architecture relies on WEF before downstream ingestion. This directly addresses the requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

B: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

C: Defender for Endpoint advanced features control optional endpoint capabilities and should be enabled when the requested investigation or protection capability depends on them. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

D: Threat indicators must be ingested through a supported threat-intelligence source or connector before they can be correlated and used in Sentinel investigations and detections. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

E: Defender for Endpoint rule settings govern endpoint-side detection and response behavior and should be adjusted at the endpoint service layer rather than by changing unrelated Sentinel analytics. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: centralize selected Windows events through Windows Event Forwarding before security ingestion.

Learning point: Configure Windows Event Forwarding so source computers forward the required Windows events to the designated collector path

Question 34

Adventure Works is revising its SOC runbook after a threat-hunting campaign. Analysts need to choose the correct Sentinel connector for the specified log source and event requirements. Which implementation should the Defender administrator select for the Americas SOC, response wave 12 while trying to improve detection coverage?

  1. Configure Defender for Endpoint device groups with the required permissions and automation level
  2. Choose and configure the Microsoft Sentinel analytics rule type that matches the detection timing and data requirements
  3. Select the Microsoft Sentinel data connector that matches the source type and required event stream
  4. Create or configure a Microsoft Sentinel playbook backed by Azure Logic Apps for the required response workflow
  5. Review and apply relevant Microsoft Sentinel SOC optimization recommendations

Correct answer: C

Why: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Option review:

A: Device groups provide scope for endpoint access and automation settings, allowing organizations to separate administration and remediation behavior for different device populations. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

B: Sentinel provides scheduled, NRT, threat-intelligence, and machine-learning analytics approaches; the correct type depends on latency, data, and detection behavior. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

C: Data connectors are the supported ingestion path for specific products and log sources, so connector selection should begin with the source and event requirements. This directly addresses the requirement: choose the correct Sentinel connector for the specified log source and event requirements.

D: Sentinel playbooks use Logic Apps to orchestrate repeatable response steps and integrations that go beyond simple incident-field automation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

E: SOC optimization recommendations identify configuration and coverage improvements that can improve the effectiveness and efficiency of the Sentinel deployment. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: choose the correct Sentinel connector for the specified log source and event requirements.

Learning point: Select the Microsoft Sentinel data connector that matches the source type and required event stream

Question 35

A ticket escalated to the incident responder at Proseware Services states one non-negotiable goal: collect the required Windows Security events with Azure Monitor Agent and a data collection rule. Which choice is the strongest fit for the high-value-assets group, response wave 12? The team also wants to support repeatable response.

  1. Configure Microsoft Defender for Endpoint custom data collection for the endpoint data required by the investigation
  2. Create a custom log table in the Log Analytics workspace for the ingested custom data
  3. Assign the least-privilege Microsoft Sentinel role that provides the required analyst or administrative capability
  4. Configure Windows Security Events via AMA and the required data collection rule
  5. Review and manage the existing Defender XDR custom detection rule, including its schedule, logic, and response actions

Correct answer: D

Why: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Option review:

A: Custom data collection extends the endpoint telemetry available to the security team for scenarios that require data beyond the default collection set. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

B: Custom log tables provide a defined schema and storage destination for data that does not belong in an existing standard Sentinel table. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

C: Microsoft Sentinel access is controlled through role-based permissions, so the correct built-in or custom role should match the job function without granting unnecessary rights. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

D: The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules to specify which Windows security events are collected into Sentinel. This directly addresses the requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

E: Managing custom detections includes maintaining query logic, frequency, alert settings, and automated actions as the environment and threat behavior change. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: collect the required Windows Security events with Azure Monitor Agent and a data collection rule.

Learning point: Configure Windows Security Events via AMA and the required data collection rule

Popular posts

img