Unit 5: Data Collection Rule (DCR) - Subjective Questions

INT328 — Network Virtualization And Cloud Security • Practice Questions with Detailed Answers

20 questions

1

Define a Data Collection Rule (DCR) in Microsoft Azure. Explain its purpose and major components.

2

Describe the steps required to create a Log Analytics workspace in the Azure portal.

3

Explain the role of a Log Analytics workspace in Azure monitoring and cloud security.

4

Distinguish between a Data Collection Rule, a Data Collection Endpoint, and a Data Collection Rule Association.

5

Explain how to configure a DCR to collect Windows Event Logs and performance counters from an Azure virtual machine.

6

Compare the Azure Monitor Agent (AMA) with legacy monitoring agents, and explain why DCRs are important for AMA.

7

What are transformations in a Data Collection Rule? Explain their benefits with a suitable example.

8

Describe the procedure for creating an Azure Storage account and discuss the important security settings that should be configured.

9

Compare Locally Redundant Storage (LRS), Zone-Redundant Storage (ZRS), Geo-Redundant Storage (GRS), and Geo-Zone-Redundant Storage (GZRS).

10

Explain how Azure Storage can be used for log archiving and security investigations. How does it differ from a Log Analytics workspace?

11

Define Microsoft Defender for Cloud and explain its two major functions: security posture management and workload protection.

12

Describe the steps involved in configuring Microsoft Defender for Cloud for an Azure subscription.

13

What is Secure Score in Microsoft Defender for Cloud? Explain how it helps improve an organization's security posture.

14

Differentiate between security recommendations, security alerts, and incidents in Microsoft cloud security services.

15

Define Microsoft Sentinel and describe its major architectural components.

16

Explain how to enable Microsoft Sentinel on a Log Analytics workspace and connect data sources.

17

Compare analytics rules, hunting queries, and workbooks in Microsoft Sentinel.

18

Describe the lifecycle of a security event in Microsoft Sentinel, from data ingestion to automated response.

19

Explain the relationship among DCR, Azure Monitor Agent, Log Analytics workspace, Microsoft Defender for Cloud, and Microsoft Sentinel.

20

Design a secure and cost-conscious log collection architecture using DCR, Log Analytics, Azure Storage, Defender for Cloud, and Microsoft Sentinel.