Microsoft Security Operations Analyst Associate SC-200 Practice Question
You run an ad-hoc Kusto Query Language (KQL) hunting query in the Microsoft Sentinel Hunting blade and find several matches for suspicious PowerShell usage. You want the same logic to execute automatically every 24 hours and raise incidents whenever results are returned, without having to manually recreate the logic elsewhere. What should you do next in the Hunting blade?
Add the query directly to an existing playbook so the playbook runs every day.
Bookmark the current results so they appear in future investigations.
Save the query to a new workbook and pin the workbook to a dashboard.
Use the Create detection rule option to convert the hunting query into a scheduled analytic rule that runs daily.
From the Hunting blade you can select a query and choose the option to create an analytic (detection) rule. This converts the existing hunting query into a scheduled query rule that runs at the chosen interval-daily, in this case-and generates alerts that can be promoted to incidents. Bookmarking results only saves the current findings for investigation; it does not provide ongoing detection. Saving the query as a workbook produces visualizations but no automated execution. Adding the query to a playbook is not possible directly and, even if it were, playbooks act on alerts rather than generate them.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Kusto Query Language (KQL)?
Open an interactive chat with Bash
What is an analytic detection rule in Microsoft Sentinel?
Open an interactive chat with Bash
What is the difference between a playbook and an analytic rule in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .