Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Microsoft Security Operations Analyst SC-200 Question # 32 Topic 4 Discussion

Microsoft Security Operations Analyst SC-200 Question # 32 Topic 4 Discussion

SC-200 Exam Topic 4 Question 32 Discussion:
Question #: 32
Topic #: 4

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. All endpoint devices are onboarded to Microsoft Defender for Endpoint.

You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace 1. All Microsoft Defender XDR events are ingested into Workspace1.

You have a Microsoft Entra tenant.

You create a KQL query named query1 that searches device logs for a known vulnerability.

You need to ensure that query1 runs every hour. The solution must minimize administrative effort.

What should you configure?


A.

an automation rule


B.

automated investigation and response (AIR)


C.

a watchlist


D.

a custom detection rule


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.