Microsoft Security Operations Analyst Associate SC-200 Practice Question
You develop a Kusto Query Language (KQL) hunting query in Microsoft Sentinel that reliably identifies credential stuffing attempts. You need the query to execute automatically every hour and raise an incident whenever at least one match is returned. Which action should you perform from the Hunting page to meet the requirement?
Pin the query to a workbook and set the workbook to refresh every 60 minutes to produce alerts.
Export the query to a Logic App playbook that calls the Log Analytics API on an hourly recurrence to send incident notifications.
Select Create detection rule and save the query as a scheduled analytics rule that runs hourly with an alert threshold of 1.
Toggle Live stream for the query so it continuously monitors data and automatically opens incidents.
Hunting queries run on-demand unless you convert them to analytics rules. By choosing Create detection rule, Microsoft Sentinel copies the query into the analytics rule wizard, where you can set a schedule (for example, every hour) and an alert threshold (results greater than or equal to 1). When the rule runs it can automatically generate incidents. Live stream only shows near-real-time results and does not create incidents, workbooks do not run queries on a schedule, and a Logic App playbook would require additional custom logic and is not the recommended method for routine scheduled detections.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Kusto Query Language (KQL)?
Open an interactive chat with Bash
Why is an Analytics Rule used for automatic incident creation in Microsoft Sentinel?
Open an interactive chat with Bash
What is the difference between a Hunting Query and an Analytics Rule in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .