Microsoft Security Operations Analyst Associate SC-200 Practice Question
You write a Kusto Query Language (KQL) hunting query in Microsoft Sentinel that detects possible data-exfiltration when large files are uploaded over an uncommon FTP port. The query must remain available in the Hunting blade so analysts can run it manually, but any future matches must automatically create incidents without analyst interaction. Which action should you take to meet the requirement?
Enable a live stream based on the query and configure email notifications for matches.
Save the query as a workbook and enable alert rules on the workbook's visualizations.
Turn on a background run schedule for the hunting query in the Hunting blade.
Select Create analytics rule for the saved hunting query and configure the scheduled query rule.
In Microsoft Sentinel, hunting queries run only when an analyst selects them. To operationalize a hunt so that it runs on a schedule and raises incidents, you convert the hunting query into a scheduled analytics rule. In the Hunting blade you do this by choosing the Create analytics rule (also displayed as Create detection rule) option for the saved query. A live stream surfaces real-time matches but does not create incidents, saving the query as a workbook simply visualizes results, and there is no background schedule toggle for hunts. Therefore, selecting Create analytics rule is the correct choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Sentinel's Hunting blade?
Open an interactive chat with Bash
How does 'Create analytics rule' differ from 'Enable live stream' in Microsoft Sentinel?
Open an interactive chat with Bash
What is Kusto Query Language (KQL) used for in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .