Unit 5: Data Collection Rule (DCR) - Practice Quiz

INT328 — Network Virtualization And Cloud Security 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the primary purpose of an Azure Log Analytics workspace?

Create Log Analytics workspace Easy
A. To create private network connections
B. To host virtual machines and applications
C. To manage user passwords and permissions
D. To store and analyze collected log data

2 Which Azure service is commonly used to query data in a Log Analytics workspace?

Create Log Analytics workspace Easy
A. Azure Virtual Desktop
B. Azure Load Balancer
C. Azure Monitor Logs
D. Azure App Service

3 Which query language is used to analyze data in a Log Analytics workspace?

Create Log Analytics workspace Easy
A. Structured Query Language
B. Hypertext Markup Language
C. Cascading Style Sheets
D. Kusto Query Language

4 Which information must be selected when creating a Log Analytics workspace?

Create Log Analytics workspace Easy
A. Virtual machine and disk size
B. Subscription and resource group
C. Username and login password
D. Firewall rule and public port

5 How can a Data Collection Rule use a Log Analytics workspace?

Create Log Analytics workspace Easy
A. As a manager of storage access keys
B. As a destination for collected data
C. As a source of virtual machine images
D. As a provider of domain names

6 What is an Azure Storage account used for?

Azure Storage account Easy
A. Creating identity access policies
B. Running operating system updates
C. Monitoring network security alerts
D. Storing cloud-based data objects

7 Which Azure Storage service is designed for unstructured object data?

Azure Storage account Easy
A. Azure Table Storage
B. Azure Blob Storage
C. Azure Queue Storage
D. Azure File Storage

8 Which naming rule applies to an Azure Storage account?

Azure Storage account Easy
A. The name must contain spaces
B. The name must include uppercase letters
C. The name must begin with a number
D. The name must be globally unique

9 Which redundancy option keeps multiple copies of data within one Azure region?

Azure Storage account Easy
A. Geo-redundant storage
B. Locally redundant storage
C. Geo-zone-redundant storage
D. Read-access geo-redundant storage

10 Which characters are allowed in an Azure Storage account name?

Azure Storage account Easy
A. Uppercase letters and numbers
B. Lowercase letters and numbers
C. Uppercase letters and underscores
D. Lowercase letters and hyphens

11 What is the main purpose of Microsoft Defender for Cloud?

Configure Microsoft Defender for Cloud Easy
A. To create database table structures
B. To design application interfaces
C. To register internet domain names
D. To improve cloud security posture

12 What does Secure Score in Microsoft Defender for Cloud represent?

Configure Microsoft Defender for Cloud Easy
A. The overall security posture
B. The cost of deployed resources
C. The speed of network traffic
D. The number of active users

13 What does Microsoft Defender for Cloud provide when it identifies a security weakness?

Configure Microsoft Defender for Cloud Easy
A. Security recommendations
B. Network IP addresses
C. Application source files
D. Storage access keys

14 Where can Defender plans be enabled for an Azure subscription?

Configure Microsoft Defender for Cloud Easy
A. Deployment history
B. Environment settings
C. Cost analysis
D. Resource visualizer

15 Which type of resource can Microsoft Defender for Cloud help protect?

Configure Microsoft Defender for Cloud Easy
A. Cloud workloads
B. Local keyboards
C. Office furniture
D. Printed documents

16 What type of service is Microsoft Sentinel?

Microsoft Sentinel Easy
A. A cloud-based file storage service
B. A relational database management service
C. A virtual machine hosting service
D. A cloud-native SIEM and SOAR service

17 What does Microsoft Sentinel use to bring data from external services into the platform?

Microsoft Sentinel Easy
A. Data connectors
B. Storage containers
C. Resource locks
D. Virtual networks

18 Which Azure resource is used to store Microsoft Sentinel log data?

Microsoft Sentinel Easy
A. Application security group
B. Azure managed disk
C. Virtual network gateway
D. Log Analytics workspace

19 What is the purpose of an analytics rule in Microsoft Sentinel?

Microsoft Sentinel Easy
A. To create storage accounts
B. To resize virtual machines
C. To assign software licenses
D. To detect suspicious activity

20 What is a playbook in Microsoft Sentinel used for?

Microsoft Sentinel Easy
A. Storing operating system files
B. Automating security responses
C. Designing network diagrams
D. Calculating monthly cloud costs

21 An organization operates resources in two Azure regions and wants centralized monitoring. What is the most appropriate design for a Log Analytics workspace?

Create Log Analytics workspace Medium
A. Create one workspace in each region only
B. Create one centralized workspace and connect resources to it
C. Create a workspace inside every resource group
D. Create one workspace only for virtual machines

22 A security team needs to retain sign-in logs for 180 days, while application logs should be retained for only 30 days. Which approach best meets this requirement?

Create Log Analytics workspace Medium
A. Store all logs in Azure Storage without workspace retention
B. Use one workspace with a 30-day retention period
C. Use separate workspaces with different retention settings
D. Use one workspace with a 180-day retention period

23 A Log Analytics workspace must be created for production monitoring. Which configuration should be selected to support access control based on Azure resource permissions?

Create Log Analytics workspace Medium
A. Resource-context access control
B. Workspace-context access control
C. Anonymous workspace access
D. Storage-account access control

24 An administrator creates a Log Analytics workspace but cannot find diagnostic logs from a virtual network resource. What should be checked first?

Create Log Analytics workspace Medium
A. Whether the virtual network uses a premium SKU
B. Whether the workspace has a public IP address
C. Whether diagnostic settings send logs to the workspace
D. Whether the workspace is linked to Azure Storage

25 A company wants to control Log Analytics costs while keeping frequently queried security data available. Which action is most suitable?

Create Log Analytics workspace Medium
A. Delete the workspace after each investigation
B. Collect only required tables and set suitable retention
C. Send every log category to the workspace
D. Disable all data collection during nonbusiness hours

26 An application stores frequently accessed transaction files and requires high availability within a region. Which redundancy option is generally the best starting choice?

Azure Storage account Medium
A. Read-access geo-redundant storage only
B. Locally redundant storage
C. Geo-redundant storage only
D. Zone-redundant storage

27 A storage account contains sensitive audit exports. The security team wants to prevent access through public endpoints. Which configuration best supports this requirement?

Azure Storage account Medium
A. Use a storage account with a shorter name
B. Enable anonymous blob access
C. Allow access from all networks
D. Use private endpoints and restrict network access

28 A company must prevent audit blobs from being modified or deleted during a required retention period. Which Azure Storage capability should be used?

Azure Storage account Medium
A. Blob soft delete only
B. Lifecycle management with immediate deletion
C. Immutable blob storage with a retention policy
D. Public read access with metadata

29 A security engineer needs to grant an automation process access to one blob container without distributing account keys. Which method is most appropriate?

Azure Storage account Medium
A. Share the storage account access key
B. Place the account name in the automation script
C. Assign an Azure role to the automation identity
D. Enable anonymous access to the container

30 An organization wants old log files moved to a cooler storage tier after 30 days and deleted after one year. Which feature should be configured?

Azure Storage account Medium
A. Azure Resource Graph queries
B. Blob index tags only
C. Azure Front Door routing
D. Storage lifecycle management

31 A security team wants Defender for Cloud to identify missing operating system updates and insecure configurations across virtual machines. Which capability should be enabled?

Configure Microsoft Defender for Cloud Medium
A. Azure Storage lifecycle management
B. Microsoft Defender for Storage only
C. Azure Cost Management
D. Microsoft Defender for Servers

32 After enabling a Defender for Cloud plan, an administrator wants to prioritize the most important security improvements. Which feature should be used?

Configure Microsoft Defender for Cloud Medium
A. Secure Score recommendations
B. Workspace retention settings
C. Storage access tiers
D. Azure subscription renaming

33 A company wants to receive alerts when a storage account shows suspicious access patterns. Which Defender for Cloud plan is most directly relevant?

Configure Microsoft Defender for Cloud Medium
A. Microsoft Defender for DNS only
B. Microsoft Purview Data Map
C. Microsoft Defender for Servers only
D. Microsoft Defender for Storage

34 A regulatory requirement states that all newly created resources must be evaluated against approved security settings. Which Defender for Cloud feature supports this goal?

Configure Microsoft Defender for Cloud Medium
A. Application Gateway caching
B. Blob versioning only
C. Regulatory compliance dashboard
D. Data transfer acceleration

35 A security operations team wants Defender for Cloud alerts to be investigated in Microsoft Sentinel. What integration should be configured?

Configure Microsoft Defender for Cloud Medium
A. A storage lifecycle rule for Sentinel
B. An access key rotation schedule only
C. A Sentinel data connector for Defender for Cloud
D. A new virtual network for each alert

36 Microsoft Sentinel is deployed for a subscription, but no sign-in data appears in its queries. What is the most likely missing configuration?

Microsoft Sentinel Medium
A. A second Sentinel workspace
B. A storage account access tier
C. A Microsoft Entra ID data connector
D. A Defender for Storage plan

37 An analyst wants Sentinel to create an incident when multiple failed sign-ins are followed by a successful sign-in from an unusual location. Which Sentinel feature should be configured?

Microsoft Sentinel Medium
A. Analytics rule
B. Storage replication policy
C. Workbook theme
D. Data retention lock

38 A security team wants a visual view of incident trends, alert sources, and investigation metrics. Which Sentinel feature is most suitable?

Microsoft Sentinel Medium
A. Workbooks
B. Data connectors only
C. Automation rules only
D. Storage containers

39 When a high-severity incident is created, the organization wants to notify the on-call team and create a service ticket automatically. Which Sentinel capability should be used?

Microsoft Sentinel Medium
A. A workspace naming convention
B. A storage access policy
C. Automation rules with a playbook
D. A workbook visualization

40 An organization wants to identify whether a suspicious IP address appears across firewall, identity, and endpoint logs. Which Sentinel capability best supports this investigation?

Microsoft Sentinel Medium
A. Blob lifecycle management
B. Incident investigation and entity correlation
C. Storage account replication
D. Log Analytics workspace creation

41 A company must keep security logs within Germany. Its virtual machines run in several Azure regions, and Microsoft Sentinel will analyze all collected logs centrally. Which workspace design best satisfies the residency requirement?

Create Log Analytics workspace Hard
A. Create the workspace in each virtual machine's region and replicate its tables to Germany automatically
B. Create one Log Analytics workspace in an approved German region and associate the required DCRs with it
C. Create one workspace in any EU region because Log Analytics data is always stored across the entire EU
D. Create a global workspace and select Germany as the destination region in each analytics rule

42 A central SOC needs access to all workspace data, while application teams must query only logs generated by Azure resources they manage. Which access model best supports both requirements?

Create Log Analytics workspace Hard
A. Use workspace access keys for the SOC and DCR association permissions for application teams
B. Use shared access signatures for the SOC and storage account RBAC for application teams
C. Use workspace-context access for the SOC and resource-context access with Azure RBAC for application teams
D. Use resource-context access for the SOC and grant application teams the workspace Contributor role

43 A workspace has a default retention period of 30 days, but the SecurityEvent table has a table-level retention setting of 180 days. Assuming no archive configuration changes the result, how long are rows in SecurityEvent retained?

Create Log Analytics workspace Hard
A. They are retained for 210 days because workspace and table retention periods are cumulative
B. They are retained for 180 days because the table-level setting overrides the workspace default
C. They are retained for 30 days because workspace retention always overrides table-level retention
D. They are retained indefinitely because a table-level setting disables automatic data deletion

44 A DCR transformation renames Computer to HostName, but the destination custom table contains a Computer column and no HostName column. Ingestion fails schema validation. What is the correct remediation?

Create Log Analytics workspace Hard
A. Configure the workspace to accept dynamic schemas for all records sent through the DCR
B. Add a query-time function that renames HostName to Computer after ingestion completes
C. Modify the transformation or destination table so the output column names and types match the table schema
D. Enable legacy agent compatibility so Log Analytics automatically restores the original column name

45 After migrating servers to Azure Monitor Agent, the SOC observes two nearly identical copies of each Windows security event in the same workspace. Each server is associated with two DCRs that collect the same event stream. What is the most appropriate correction?

Create Log Analytics workspace Hard
A. Remove the overlapping event collection from one DCR or redesign the DCR associations
B. Change one DCR to use resource-context access while leaving both collection definitions unchanged
C. Enable workspace deduplication and retain both DCR associations for collection resilience
D. Reduce workspace retention so the duplicate records are deleted immediately after correlation

46 A diagnostic setting for a regional Azure resource is configured to archive logs to a storage account, but deployment validation rejects the destination. The account is in a different Azure region, while its firewall and permissions are correctly configured. What is the likely cause?

Azure Storage account Hard
A. A regional resource generally requires the diagnostic storage destination to be in the same region
B. The storage account must contain a manually created container before the setting is deployed
C. Diagnostic settings cannot send logs to storage accounts protected by Azure Resource Manager
D. Diagnostic settings require the storage account to use locally redundant storage exclusively

47 Security logs are stored in an immutable container with a locked 365-day time-based retention policy. A lifecycle rule attempts to delete the blobs after 90 days. What will happen?

Azure Storage account Hard
A. The blobs are deleted after 90 days but remain recoverable through container soft delete for 275 days
B. The lifecycle rule shortens the immutable retention period because it was created after the policy
C. The lifecycle rule deletes the blobs because lifecycle management takes precedence over immutability
D. Deletion is blocked until the immutable retention period expires, even though the lifecycle rule matches

48 An archive must remain available after a zonal failure and must provide read access from a secondary Azure region if the primary region becomes unavailable. Which redundancy option best satisfies both requirements?

Azure Storage account Hard
A. Geo-zone-redundant storage
B. Read-access geo-redundant storage
C. Read-access geo-zone-redundant storage
D. Zone-redundant storage

49 A lifecycle rule moves diagnostic log blobs to the Cool tier 30 days after creation. Some blobs are unexpectedly moved later because a metadata operation changed their last-modified time. Which lifecycle behavior explains this?

Azure Storage account Hard
A. Lifecycle age conditions begin when the diagnostic setting creates its destination container
B. Lifecycle age conditions are evaluated using the blob's last-modified time rather than an embedded event timestamp
C. Lifecycle age conditions begin only after the blob has remained unchanged for one complete billing cycle
D. Lifecycle age conditions are evaluated using the newest log record stored inside each blob

50 An ADLS Gen2 storage account is reachable only through private endpoints. Blob API operations succeed, but analytics clients using hierarchical namespace operations fail DNS resolution for the Data Lake endpoint. What should be added?

Azure Storage account Hard
A. A second blob private endpoint in the same virtual network
B. A dfs private endpoint and corresponding private DNS configuration
C. A queue private endpoint and corresponding private DNS configuration
D. A file private endpoint and corresponding private DNS configuration

51 A security team needs attack-path analysis, cloud security explorer capabilities, and risk-prioritized recommendations across Azure resources. Enabling only the foundational Defender for Cloud posture features does not provide them. Which plan is required?

Configure Microsoft Defender for Cloud Hard
A. Microsoft Defender for Servers Plan 1
B. Microsoft Defender for Resource Manager
C. Microsoft Defender Cloud Security Posture Management
D. Microsoft Defender for Storage

52 Defender for Servers Plan 2 is enabled on one subscription. Virtual machines in another subscription under the same management group remain uncovered. What is the most scalable correction?

Configure Microsoft Defender for Cloud Hard
A. Enable Microsoft Sentinel on the management group so Defender plans are inherited automatically
B. Associate all virtual machines with the Log Analytics workspace used by the protected subscription
C. Move the uncovered virtual machines into a resource group belonging to the protected subscription
D. Use an Azure Policy initiative or management-group governance process to enable the plan on every required subscription

53 A legacy system temporarily cannot satisfy a Defender for Cloud recommendation. The security team must document the accepted risk, identify an owner, and automatically revisit the decision after 60 days. What should it configure?

Configure Microsoft Defender for Cloud Hard
A. A Sentinel analytics rule that closes incidents generated by the recommendation
B. A permanent dismissal of the recommendation at the management-group scope
C. A DCR transformation that removes the associated assessment records before ingestion
D. A recommendation exemption with justification, scope, and an expiration date

54 Administrators must access management ports on Azure virtual machines only after an approved request, and the ports should remain closed outside the approved interval. Which Defender capability directly addresses this requirement?

Configure Microsoft Defender for Cloud Hard
A. Agentless machine scanning in Defender Cloud Security Posture Management
B. Sensitive data discovery in Microsoft Defender for Storage
C. Adaptive application controls in Defender for Servers Plan 1
D. Just-in-time virtual machine access in Defender for Servers Plan 2

55 Defender for Cloud reports vulnerabilities discovered through agentless scanning, but no corresponding raw vulnerability records appear in a custom Log Analytics table populated by an Azure Monitor Agent DCR. What is the best interpretation?

Configure Microsoft Defender for Cloud Hard
A. The workspace must use the legacy Log Analytics agent because agentless scanning is incompatible with Azure Monitor Agent
B. The DCR must collect the SecurityEvent stream before Defender can expose any agentless vulnerability findings
C. Agentless scanning analyzes snapshots independently of the Azure Monitor Agent and does not require records to pass through that DCR
D. Agentless scanning writes findings to every DCR-associated workspace only after workspace retention reaches 90 days

56 A SOC needs an analytics rule that evaluates events approximately once per minute and minimizes detection delay without using a custom continuous polling service. Which Sentinel rule type is most appropriate?

Microsoft Sentinel Hard
A. A near-real-time analytics rule
B. A hunting query stored as a favorite
C. A Microsoft security incident creation rule
D. A scheduled analytics rule running hourly

57 A large Sentinel watchlist contains malicious IP addresses. A scheduled rule must efficiently compare SigninLogs.IPAddress with the watchlist. Which design is most appropriate?

Microsoft Sentinel Hard
A. Convert every sign-in record to JSON and compare the complete record with the watchlist
B. Run one _GetWatchlist call for each sign-in event and filter the results in a loop
C. Configure the IP field as the watchlist SearchKey and join it with SigninLogs.IPAddress
D. Store all IP fields in one watchlist column and use contains against the serialized row

58 A DCR transformation discards all successful sign-in events before they reach the Sentinel workspace. Investigators later need those events to establish a user's normal sign-in locations. Which statement is correct?

Microsoft Sentinel Hard
A. Microsoft Defender for Cloud automatically recreates the events when an investigation graph is opened
B. The discarded events cannot be recovered from Sentinel, so the ingestion design must retain or separately route required events
C. Sentinel can reconstruct the discarded events from failed sign-ins by enabling user and entity behavior analytics
D. The events remain hidden in the workspace archive and become searchable after an archive restoration operation

59 A detection must work across authentication data from several vendors whose native tables use different column names and schemas. Which Sentinel approach minimizes vendor-specific query logic?

Microsoft Sentinel Hard
A. Rename every source table to SigninLogs through a workspace transformation
B. Export each source to storage and run one separate analytics rule per container
C. Convert every table to SecurityEvent by changing its DCR stream declaration
D. Query an Authentication ASIM parser that normalizes the vendor-specific schemas

60 A central SOC must investigate Sentinel data in several customer tenants while each customer retains its own workspace and billing boundary. Which architecture best supports delegated cross-tenant operations?

Microsoft Sentinel Hard
A. Share each workspace ID and primary key with SOC analysts for interactive portal access
B. Use Azure Lighthouse delegation with appropriate Sentinel and Log Analytics roles in each tenant
C. Create one DCR in the SOC tenant and associate it directly with all cross-tenant workspaces
D. Move every customer workspace into the SOC tenant while leaving customer subscriptions unchanged