ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 28 - SC-200 discussion

Report
Export

You are configuring Azure Sentinel.

You need to send a Microsoft Teams message to a channel whenever a sign-in from a suspicious IP address is detected.

Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Add a playbook.

Answers
A.

Add a playbook.

B.

Associate a playbook to an incident.

Answers
B.

Associate a playbook to an incident.

C.

Enable Entity behavior analytics.

Answers
C.

Enable Entity behavior analytics.

D.

Create a workbook.

Answers
D.

Create a workbook.

E.

Enable the Fusion rule.

Answers
E.

Enable the Fusion rule.

Suggested answer: A, B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook

asked 05/10/2024
Marcel Engelbrecht
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first