Microsoft SC-200 Question Answer
You have an Azure subscription that contains a Log Analytics workspace named Workspace1.
You configure Azure activity logs and Microsoft Entra ID logs to be forwarded to Workspace1.
You need to identify which Azure resources have been queried or modified by risky users.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Microsoft SC-200 Summary
- Vendor: Microsoft
- Product: SC-200
- Update on: Jul 30, 2025
- Questions: 370