Configure detections
4 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
Counting incidents created when four independent Sentinel analytics rules all fire for one action
A Sentinel workspace with four separate Microsoft security analytics rules; when User1's action matches all four, each rule generates its own alert an
Setting a custom detection rule frequency to identify C2 communication within the past 14 days
A custom detection rule must identify devices that communicated in the past 14 days and minimize identification delay; the Every 24 hours frequency us
Creating a scheduled query rule from a hunting query so detections generate incidents
After a hunting query finds a new MITRE-mapped attack vector, convert it into a scheduled query rule so it runs on a schedule and automatically create
Finding enabled anomaly rules in Sentinel on the Analytics page Anomalies tab
To see which anomaly detection rules are enabled in a Microsoft Sentinel workspace, review the Anomalies tab on the Analytics page, where anomaly rule