ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 58 - SC-200 discussion

Report
Export

You create a hunting query in Azure Sentinel.

You need to receive a notification in the Azure portal as soon as the hunting query detects a match on the query. The solution must minimize effort.

What should you use?

A.

a playbook

Answers
A.

a playbook

B.

a notebook

Answers
B.

a notebook

C.

a livestream

Answers
C.

a livestream

D.

a bookmark

Answers
D.

a bookmark

Suggested answer: C

Explanation:


Use livestream to run a specific query constantly, presenting results as they come in.

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/hunting

asked 05/10/2024
Zachary Janssen
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first