Microsoft Security Operations Analyst Associate SC-200 Practice Question
You need Microsoft Sentinel to raise an alert whenever a user's count of failed sign-ins during one hour is statistically higher than the user's own historical pattern. You create a new analytics rule and write a Kusto query that returns the failed sign-in events with the Username field mapped to the Account entity. Which rule type should you select in the wizard to automatically apply time-series anomaly detection without having to set a fixed threshold?
To compare each user's current activity to that same user's historical baseline, you must use the Anomaly rule type in Microsoft Sentinel. An Anomaly rule applies Sentinel's built-in time-series behavioral analytics models to the query's result set, learning normal patterns per entity (such as an individual account) and raising alerts only when the current value significantly deviates from the learned baseline. Scheduled query rules use static or dynamic thresholds that you configure manually, and Fusion or Machine learning rules do not support custom Kusto queries.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Kusto Query Language (KQL)?
Open an interactive chat with Bash
How does Microsoft Sentinel use time-series anomaly detection?
Open an interactive chat with Bash
What is the difference between Anomaly rules and Scheduled query rules in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .