ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 54 - SC-200 discussion

Report
Export

You are configuring Azure Sentinel.

You need to send a Microsoft Teams message to a channel whenever an incident representing a sign-in risk event is activated in Azure Sentinel.

Which two actions should you perform in Azure Sentinel? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Enable Entity behavior analytics.

Answers
A.

Enable Entity behavior analytics.

B.

Associate a playbook to the analytics rule that triggered the incident.

Answers
B.

Associate a playbook to the analytics rule that triggered the incident.

C.

Enable the Fusion rule.

Answers
C.

Enable the Fusion rule.

D.

Add a playbook.

Answers
D.

Add a playbook.

E.

Create a workbook.

Answers
E.

Create a workbook.

Suggested answer: A, B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/enable-entity-behavior-analytics

https://docs.microsoft.com/en-us/azure/sentinel/automate-responses-with-playbooks

asked 05/10/2024
DIPESH JAISWAL
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first