フリー問題

Implementing End-to-End Security Controls for Cloud and AI Workloads (SC-500) のフリー問題 20 / 20 問目

問題文

An investigation must combine Azure resource activity, Microsoft 365 administrative actions, and sign-in events. Which approach makes this practical?

選択肢

  1. Collect each of these sources into the workspace with the appropriate connectors, so they can be correlated in one place, and confirm the retention covers the investigation window
  2. Rely on Security Copilot to reach all sources without any collection
  3. Export all three sources to storage accounts and analyze them offline with external tools, so the workspace cost stays low and the raw records are preserved
  4. Query each source in its own portal, note the timestamps of the relevant events, and reconcile the results by hand into a single timeline for the investigation, confirming that each source still holds the events for that window

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。