SC-200 Manage a security operations environment • Set 15
SC-200 Manage a security operations environment Practice Test 15 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Sentinel with Azure Monitor Agent (AMA) to collect Windows security events. You need to collect process creation events (Event ID 4688) and include command-line information. The current Data Collection Rule (DCR) collects only basic security events. What should you modify?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.