FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 4

Question 188

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have three Azure subscriptions. Each subscription contains multiple virtual machines that run Windows Server. You have a Microsoft Sentinel workspace. You need to ensure that failed sign-in attempts from all the virtual machines can be analyzed by using Microsoft Sentinel. The solution must minimize administrative effort. What should you do first?

  • AFrom the Microsoft Defender portal, install the Windows Security Events solution.
  • BOn each virtual machine, create an event subscription.
  • COn each virtual machine, install the Azure Connected Machine agent.
  • DFrom the Microsoft Defender portal, install the Syslog solution.