Microsoft Security Operations Analyst SC-200 Question # 9 Topic 1 Discussion

Microsoft Security Operations Analyst SC-200 Question # 9 Topic 1 Discussion

SC-200 Exam Topic 1 Question 9 Discussion:
Question #: 9
Topic #: 1

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint

You need to create a query that will link the Alertlnfo, AlertEvidence, and DeviceLogonEvents tables. The solution must return all the rows in the tables.

Which operator should you use?


A.

join kind = inner


B.

evaluate hint. Remote =


C.

search *


D.

union kind = inner


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.