Weekend Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: CFsave75

Microsoft Certified: Cloud and AI Security Engineer Associate SC-500 Question # 1 Topic 1 Discussion

Microsoft Certified: Cloud and AI Security Engineer Associate SC-500 Question # 1 Topic 1 Discussion

SC-500 Exam Topic 1 Question 1 Discussion:
Question #: 1
Topic #: 1

You have a Microsoft Sentinel workspace named Workspace1

You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.

You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:

•Ensure that filtering occurs before data is written to Workspace1

•Reduce ingestion costs by excluding low value Syslog messages.

What should you include in the solution?


A.

An Advanced Security Information Model (ASIM) parser


B.

A data collection rule (DCR)


C.

An analytics rule


D.

A table-level filter and split transformation


Get Premium SC-500 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.