Microsoft Security Operations Analyst Associate SC-200 Practice Question
In Microsoft Defender XDR, you create a custom detection rule based on an advanced hunting query that identifies PowerShell processes spawned by Office applications. The rule must generate a high-severity alert only if the query returns at least three distinct devices within a 30-minute window. Which detection rule configuration meets the requirement?
Create a threshold rule that counts the number of distinct devices, set the threshold to 3, and define a 30-minute look-back period with High severity.
Create a threshold rule based on the number of total events, set the threshold to 3, and define a 24-hour look-back period with High severity.
Create a real-time rule that triggers on every matching event and sets the severity to Informational.
Create a scheduled rule that runs every 30 minutes and always raises a High-severity alert when the query returns any results.
To alert only when a minimum number of unique entities is reached, you must use a threshold-based custom detection. Selecting "Number of distinct devices" as the threshold type lets the rule count unique DeviceId values returned by the query. Setting the threshold to 3 and the look-back period to 30 minutes ensures an alert is raised only if three or more separate devices match the query during that time. Choosing any scheduled rule without a threshold would fire on every match, while setting the threshold to total events or distinct users would not guarantee three different devices triggered the condition.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a threshold-based detection rule in Microsoft Defender XDR?
Open an interactive chat with Bash
What is the difference between distinct devices and total events in detection rules?
Open an interactive chat with Bash
Why is a 30-minute look-back period important for threshold rules in this scenario?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .