Finding enabled anomaly rules in Sentinel on the Analytics page Anomalies tab
You have a Microsoft Sentinel workspace named SW1. You need to identify which anomaly rules are enabled in SW1. What should you review in Microsoft Sentinel?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Sentinel surfaces its built-in anomaly rules under the Analytics page's Anomalies tab rather than Content hub, Entity behavior, or Settings, making Analytics the place to review their status.
To see which anomaly detection rules are enabled in a Microsoft Sentinel workspace, review the Anomalies tab on the Analytics page, where anomaly rules are displayed in a grid showing their enabled state.
Looking in Entity behavior or Content hub — those manage UEBA configuration and solution content respectively, not the grid of enabled anomaly rules.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Sentinel lists anomaly rules in a grid on the Anomalies tab within the Analytics page, where you can see which anomaly rules are enabled. This is the designated location for reviewing anomaly-rule status.Why the Other Options Are Wrong
Content hub (A) is for deploying and managing solution content. Entity behavior (B) configures user and entity behavior analytics but does not list anomaly rules. Settings (D) holds workspace configuration, not the anomaly-rule grid.Community Comment Notes
The community is unanimous (C 100). rsanx42 (9 likes) cites the work-with-anomaly-rules documentation, noting anomaly rules appear in the Anomalies tab of the Analytics page.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →