Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization ingests data from dozens of sources into a single Microsoft Sentinel workspace. To keep costs predictable, you must receive an alert whenever the amount of data written to any table suddenly surges beyond its historical baseline. You want to rely on Microsoft Sentinel's built-in monitoring features and avoid writing a custom Kusto Query Language (KQL) rule. Which capability should you enable first to meet the requirement?
Deploy the Usage and estimated costs workbook and configure email notifications.
Enable the Ingestion volume anomalies analytics rule template.
Configure a daily cap on data ingestion for the workspace.
Enable the Entity behavior analytics rule template.
Microsoft Sentinel includes a built-in analytics rule template named Ingestion volume anomalies. When enabled, the rule automatically learns normal ingestion patterns for each table and generates an incident if the current volume sharply exceeds the historical baseline. A daily cap limits cost but produces no alert, the Usage and estimated costs workbook is only for interactive review, and the Entity behavior analytics template focuses on user and host behavior rather than ingestion metrics.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does the Ingestion volume anomalies analytics rule template work?
Open an interactive chat with Bash
What is the difference between the Ingestion volume anomalies analytics rule and the Entity behavior analytics rule?
Open an interactive chat with Bash
Why wouldn't a daily cap on data ingestion meet the requirement for alerts on surges?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .