Microsoft Security Operations Analyst Associate SC-200 Practice Question
During threat-hunting in Microsoft Sentinel you run a KQL query that surfaces suspicious sign-in events. You must: save each event with its full context, annotate it with comments and MITRE ATT&CK tactics, and allow an analytics rule to later promote it to an incident. Which Sentinel feature meets all these requirements?
Insert the events into a custom Log Analytics table and enable change tracking
Export the query results to a watchlist and reference the list in a scheduled analytics rule
Save the query as a function and pin its results in a workbook visualization
Create a hunting bookmark for each event and add relevant tags and tactics
Hunting bookmarks let investigators preserve the original event record, attach comments, tags, and MITRE ATT&CK tactics, and store entities. By enabling the built-in "Create incidents from hunting bookmarks" analytics rule template, bookmarked events can automatically generate incidents. Watchlists only store reference data, while custom Log Analytics tables and workbook visualizations do not keep full event context or provide direct incident promotion.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a hunting bookmark in Microsoft Sentinel?
Open an interactive chat with Bash
What are MITRE ATT&CK tactics, and why are they important in threat-hunting?
Open an interactive chat with Bash
How can an analytics rule use hunting bookmarks in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .