SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel with Azure Monitor Agent (AMA) to collect Windows security events. You need to collect process creation events (Event ID 4688) and include command-line information. The current Data Collection Rule (DCR) collects only basic security events. What should you modify?
⚠ Common exam trap
Watch out — candidates often assume modifying the DCR to include the event ID is sufficient, but they overlook the prerequisite Windows policy that must be enabled to populate the command-line data within the event itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'Include command line in process creation events' policy in Windows Group Policy.
Event ID 4688 (process creation) can include command-line arguments, but this data is not captured by default. The 'Include command line in process creation events' Group Policy setting must be enabled on the Windows machines to populate the CommandLine field in the security event log. Without this policy, the AMA and DCR will collect the event but the command-line information will be empty.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Upgrade the AMA to the latest version.
Why it's wrong here
Upgrading the Azure Monitor Agent (AMA) to the latest version only changes the telemetry collection agent's transport, health, and feature logic. It cannot alter the content Windows writes to the Security event log, so if Event 4688 is generated without a command line, the AMA version is irrelevant. The missing command-line value is an auditing-policy issue at the endpoint, not an agent-version deficiency, so an upgrade will not restore command-line data.
- ✓
Enable the 'Include command line in process creation events' policy in Windows Group Policy.
Why this is correct
This is the correct fix because Windows does not record command-line arguments in Event ID 4688 unless the 'Include command line in process creation events' policy is enabled. The setting is located under Computer Configuration > Administrative Templates > System > Audit Process Creation and, when set to Enabled, adds the Process Command Line field to each generated 4688 event. Without this Group Policy (or local security policy) change, Microsoft Sentinel receives the event but the command-line field remains empty, which severely degrades process-investigation and hunting value.
- ✗
Modify the DCR to include Event ID 4688 in the data source.
Why it's wrong here
Modifying the data collection rule (DCR) to include Event ID 4688 only controls whether that event ID is filtered and forwarded to Log Analytics. If the Security log already contains 4688 events, the event is likely being collected, but the CommandLine property is blank because Windows did not log it. Updating the DCR cannot retroactively populate command-line data or change how the operating system audits process creation; it merely selects which log records are sent to Sentinel. This option is therefore ineffective unless the audit policy itself is corrected first.
- ✗
Switch to the Windows Security Events via Legacy Agent connector.
Why it's wrong here
Switching from the Azure Monitor Agent to the Windows Security Events via Legacy Agent connector would change the collection pipeline from AMA/DCR to the Log Analytics agent's event settings, but both connectors depend on the same underlying Windows Security log content. The legacy agent still reads Event ID 4688 and forwards the fields Windows chooses to include, so it also requires the 'Include command line in process creation events' policy to be enabled. Migrating connectors would interrupt existing collection and introduce a different infrastructure without solving the root cause; there is no mechanism in the legacy agent to enrich events with command-line data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.