Microsoft Security Operations Analyst Associate SC-200 Practice Question
You create a new scheduled analytics rule in Microsoft Sentinel that runs a Kusto query against Azure AD sign-in logs and returns the columns UserPrincipalName and IPAddress. You need every alert that the rule generates to automatically display the signed-in user and the source IP address as entities in the investigation graph so they can participate in incident correlation. Which configuration should you add before saving the rule?
Configure aggregation settings to group alerts by the UserPrincipalName and IPAddress fields.
Add UserPrincipalName and IPAddress as custom details in the alert enrichment section of the rule.
Enable incident creation and configure custom incident settings so that UserPrincipalName and IPAddress appear in the incident details.
In the Entity mapping section, map UserPrincipalName to the Account entity (Name) and IPAddress to the IPv4 entity (Address).
Microsoft Sentinel's investigation graph and fusion correlation engine rely on entity data that is explicitly mapped in an analytics rule. In a scheduled analytics rule you use the Entity mapping section (under Set rule logic) to link columns returned by the query to the built-in entity schema. Mapping the UserPrincipalName column to the Account entity's Name field and the IPAddress column to the IPv4 (or IP) entity's Address field makes those values available as entities on every alert. Other settings-such as alert enrichment, incident creation, or aggregation-do not produce entities unless the data is first mapped in the Entity mapping section.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is entity mapping in Microsoft Sentinel?
Open an interactive chat with Bash
How does the investigation graph use entities in Microsoft Sentinel?
Open an interactive chat with Bash
Why is alert enrichment not sufficient for entity correlation in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .