FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 4

Question 172

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have an on-premises Linux server that runs a background process named App1 and has the Azure Connected Machine agent installed. You have a Microsoft Sentinel workspace named WS1. You need to configure a data collection rule (DCR) named DCR1 that will use the Syslog via AMA connector to collect messages related to App1. The solution must meet the following requirements: • Only collect messages that have a priority level of critical. • Minimize the volume of data collected. Which facility and log level should you configure for DCR1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question 172