Microsoft Security Operations Analyst SC-200 Question # 23 Topic 3 Discussion

Microsoft Security Operations Analyst SC-200 Question # 23 Topic 3 Discussion

SC-200 Exam Topic 3 Question 23 Discussion:
Question #: 23
Topic #: 3

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR.

The security team at your company detects command and control (C2) agent traffic on the network. Agents communicate once every 50 hours.

You need to create a Microsoft Defender XDR custom detection rule that will identify compromised devices and establish a pattern of communication. The solution must meet the following requirements:

• Identify all the devices that have communicated during the past 14 days.

• Minimize how long it takes to identify the devices.

To what should you set the detection frequency for the rule?


A.

Every three hours


B.

Every 24 hours


C.

Every hour


D.

Every 12 hours


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.