Microsoft Security Operations Analyst SC-200 Question # 51 Topic 6 Discussion

Microsoft Security Operations Analyst SC-200 Question # 51 Topic 6 Discussion

SC-200 Exam Topic 6 Question 51 Discussion:
Question #: 51
Topic #: 6

You have an Azure subscription named Sub1. Sub1 contains a Microsoft Sentinel workspace named SW1 and a virtual machine named VM1 that runs Windows Server. SW1 collects security logs from VM1 by using the Windows Security Events via AMA connector.

You need to limit the scope of events collected from VM1. The solution must ensure that only audit failure events are collected.

How should you complete the filter expression for the connector? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-200 Question 51


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.