ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 53 - SC-200 discussion

Report
Export

You are investigating an incident in Azure Sentinel that contains more than 127 alerts.

You discover eight alerts in the incident that require further investigation.

You need to escalate the alerts to another Azure Sentinel administrator.

What should you do to provide the alerts to the administrator?

A.

Create a Microsoft incident creation rule

Answers
A.

Create a Microsoft incident creation rule

B.

Share the incident URL

Answers
B.

Share the incident URL

C.

Create a scheduled query rule

Answers
C.

Create a scheduled query rule

D.

Assign the incident

Answers
D.

Assign the incident

Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/investigate-cases

asked 05/10/2024
Narender B
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first