Configuring Data Collection Rules

5 questions Pass: 70% +15 pts

Quiz covering Security Monitoring and Automation

Configuring Data Collection Rules

5 questions | Pass: 70% | Earn 15 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which Azure resource is required to define how data is collected from a virtual machine into a Log Analytics workspace using the Azure Monitor agent?

  2. 2

    You need to collect Windows Event logs from a fleet of Azure virtual machines and send them to Microsoft Sentinel. Which component must be installed on the virtual machines to support Data Collection Rules?

  3. 3

    When configuring a Data Collection Rule for Linux virtual machines, which format is used to define the specific syslog facilities and severity levels to be collected?

  4. 4

    You are creating a Data Collection Rule to ingest Windows Event logs. You only want to collect 'Security' events with Event ID 4624. Which filtering method should you use within the DCR?

  5. 5

    If you have a Data Collection Rule configured with a transformation, at what stage of the data pipeline is that transformation applied?