You have a Log Analytics workspace (Workspace1) and 100 Windows Server VMs. Microsoft Defender for Servers Plan 2 is enabled and configured to monitor Windows file and registry changes on the VMs. Which Log Analytics table should you query to retrieve the detected file and registry change events?
Choose an answer
Tap an option to check your answer.
Correct answer: DeviceRegistryEvents.
Why this is the answer
The correct table is DeviceRegistryEvents. This table is part of the Microsoft Defender for Endpoint schema and is specifically designed to store registry event data, including changes detected by Defender for Servers. Since Defender for Servers Plan 2 is enabled and configured for file and registry monitoring, this is the most direct and accurate source for registry change events. ASimRegistryEventLogs and ASimFileEventLogs are part of the Azure Sentinel Information Model (ASIM), which normalizes data from various sources. While useful for unified querying across different security solutions, they are not the raw source tables for Defender for Endpoint data. MDCDetectionFimEvents is not a standard Log Analytics table for this specific purpose.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed