Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are creating a custom detection rule in Microsoft Defender XDR to raise an alert when more than three PowerShell processes on the same device run a base-64 encoded command within one hour. You have written and validated the following Advanced Hunting query:
DeviceProcessEvents
| where ProcessCommandLine has "-EncodedCommand"
| summarize EventCount = count() by DeviceId, bin(Timestamp, 1h)
| where EventCount > 3
After pasting the query into the rule wizard, which additional configuration must you set so that the alert groups the matching process events by device and displays the EventCount value produced by the summarize clause?
Enable the Trigger alert only when threshold is reached option and set the threshold to 3.
Enter DeviceId in the Aggregation column setting.
Set Group by entity to Device ID.
Change the query schedule to Every 5 minutes with a 1-hour look-back window.
Because the query uses summarize to aggregate events, the custom detection rule must know which column represents the aggregation key so it can group the individual events into a single alert and surface the aggregated fields (such as EventCount). You accomplish this by populating the Aggregation column setting with the name of the column you used in the summarize clause-in this case, DeviceId. Selecting any other column, leaving the field blank, or configuring scheduling or suppression options will not make the wizard include the summarized count in the alert or correctly group the events.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Aggregation column in Microsoft Defender XDR?
Open an interactive chat with Bash
Why is Entering DeviceId in the Aggregation column necessary for this query?
Open an interactive chat with Bash
When should you use the summarize clause in an Advanced Hunting query?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .