Microsoft Security Operations Analyst Associate SC-200 Practice Question
While investigating a potential command-and-control (C2) beacon, you need to query Microsoft Sentinel for DNS-related activity across all data sources that support the Advanced Security Information Model (ASIM). The query must automatically normalize the different source logs and return the common schema fields such as DnsQuery, DnsResponseName, SrcIpAddr, and Computer. Which Kusto query function should you start the query with to meet these requirements?
ASIM supplies ready-made Kusto functions-also called parsers-that union the relevant tables from every connected data source and project the fields defined in the ASIM schema. For DNS investigations you call the imDns() parser (sometimes surfaced as _Im_Dns). This function brings together DNS events from sources such as Microsoft Defender for Endpoint, DNS analytics logs, and Sysmon, and standardizes them to the DNS activity schema, exposing fields like DnsQuery, DnsResponseName, SrcIpAddr, and Computer. Using generic tables like SecurityEvent or DeviceNetworkEvents directly would miss data from other sources, and the UnifiedTables function is intended for UEBA enrichment, not ASIM normalization. Therefore, starting the query with imDns() is the correct approach.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ASIM in Microsoft Sentinel?
Open an interactive chat with Bash
How does the imDns() parser work in Microsoft Sentinel?
Open an interactive chat with Bash
Why should SecurityEvent or DeviceNetworkEvents not be used for DNS-specific queries in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .