Microsoft Security Operations Analyst Associate SC-200 Practice Question
You created a Kusto Query Language (KQL) statement in Log Analytics to look for repeated RDP connections from the same external IP address. You now want other analysts to be able to run this query from the Hunting blade in Microsoft Sentinel and to track the results over time. In the Hunting pane, which action must you take so the query is saved as a managed hunting query that Sentinel can execute on demand and show in the hunting dashboard?
Publish the query by converting it to an analytics rule.
Select "Run Query" and then pin the results to a workbook.
Click "Export" to save the KQL script to your workstation.
Choose "Save & Run," add the required metadata, and then confirm.
In Microsoft Sentinel, a query does not become a managed hunting query until it is explicitly saved in the Hunting blade. Choosing Save & Run stores the query (together with its metadata such as description, tactics, and required tables) in the Sentinel repository of hunting queries and immediately executes it once. That makes the query appear in the hunting dashboard for any analyst to run again or monitor later. Simply running the query, exporting it, or pinning its result to a workbook does not register it as a hunting query, so it will not show up in the list of saved hunts.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Kusto Query Language (KQL)?
Open an interactive chat with Bash
What metadata must be added to a managed hunting query in Microsoft Sentinel?
Open an interactive chat with Bash
What is the purpose of the Hunting blade in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .