Microsoft Security Operations Analyst SC-200 Question # 27 Topic 3 Discussion

Microsoft Security Operations Analyst SC-200 Question # 27 Topic 3 Discussion

SC-200 Exam Topic 3 Question 27 Discussion:
Question #: 27
Topic #: 3

You need to ensure that the processing of incidents generated by rulequery1 meets the Microsoft Sentinel requirements.

What should you create first?


A.

a playbook with an incident trigger


B.

a playbook with an entity trigger


C.

an Azure Automation rule


D.

a playbook with an alert trigger


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.