Configure the Microsoft Sentinel SIEM and platform
4 practice questions under this official exam objective (SC-200) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
Assigning Workbook Contributor so a user can deploy and customize Sentinel workbook templates under least privilege
To let User1 deploy and customize Microsoft Sentinel workbook templates on RG1 under least privilege, assign the Workbook Contributor (Azure Monitor)
Assigning the Microsoft Sentinel Responder role so a user can investigate incidents under least privilege
User1 must investigate Sentinel incidents with least privilege; the Microsoft Sentinel Responder role grants view, status-update, and comment rights o
Choosing the Azure Activity workbook to analyze subscription-level administrative actions in Microsoft Sentinel
After deploying the Microsoft Entra solution to a Sentinel workspace, you need to analyze actions performed by users with administrative privileges to
Adding a query to a Sentinel workbook to build a timechart of SecurityEvent counts by day
To show the count of SecurityEvent rows ingested over the past week as a daily timechart in a Sentinel workbook, add a query that filters by time, agg