Microsoft Security, Compliance, and Identity Fundamentals SC-900 Practice Question
You are new to Microsoft Sentinel and want to be alerted when a specific security event occurs across your Azure and on-premises logs. Which Sentinel capability allows you to create queries that run on a schedule and generate incidents when their conditions are met?
In Microsoft Sentinel, analytics rules are used to implement threat detection logic. You define a Kusto Query Language (KQL) query that looks for indicators of compromise in the data collected by Sentinel. The rule runs on a configurable schedule, evaluates the query results, and automatically creates an incident if the defined threshold or condition is met.
Other options do not provide this functionality:
Data connectors are used to ingest data from various sources into Sentinel but do not generate alerts by themselves.
Workbooks offer interactive dashboards for visualizing data and reporting but do not trigger incidents.
Playbooks (built on Azure Logic Apps) automate responses after an alert or incident has been generated; they do not detect threats on their own.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Kusto Query Language (KQL)?
Open an interactive chat with Bash
How do analytics rules work in Microsoft Sentinel?
Open an interactive chat with Bash
What are data connectors in Microsoft Sentinel used for?
Open an interactive chat with Bash
Microsoft Security, Compliance, and Identity Fundamentals SC-900
Describe the capabilities of Microsoft security solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .