Microsoft Security Operations Analyst SC-200 Question # 6 Topic 1 Discussion

Microsoft Security Operations Analyst SC-200 Question # 6 Topic 1 Discussion

SC-200 Exam Topic 1 Question 6 Discussion:
Question #: 6
Topic #: 1

You need to implement the scheduled rule for incident generation based on rulequery1.

What should you configure first?


A.

entity mapping


B.

custom details


C.

event grouping


D.

alert details


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.