SC-200 • Practice Exam 64
Free SC-200 practice exam — 20 questions with explanations. Set 64. No signup required.
Your organization uses Microsoft Sentinel with a workspace in the East US region. You need to respond to an incident involving data exfiltration from a virtual machine in West Europe. The incident was created from a custom analytics rule that queries the AzureActivity table. What should you do to ensure the incident contains all relevant evidence from the West Europe region?