Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are writing a Kusto Query Language (KQL) query for a scheduled analytics rule in Microsoft Sentinel. The query returns a column named UserPrincipalName that contains the sign-in name of the offending account. You need Microsoft Sentinel to recognize this value as a user entity so that it appears automatically on the investigation graph without any further manual mapping in the rule wizard.
Microsoft Sentinel detects entities in query results when the column name matches the pattern CustomEntity. By adding an extend statement that creates a new column named AccountCustomEntity and sets it equal to the existing UserPrincipalName field, Sentinel will classify every value in that column as a user account entity. Renaming the original column or projecting it under another name will not trigger automatic entity recognition unless the CustomEntity suffix is used, and there is no KQL function that converts a field into an entity implicitly.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of the 'extend' operator in KQL?
Open an interactive chat with Bash
Why does Microsoft Sentinel require the '<EntityType>CustomEntity' suffix for entity recognition?
Open an interactive chat with Bash
What types of entities can Microsoft Sentinel recognize automatically?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .