ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 155 - SC-200 discussion

Report
Export

HOTSPOT

You have a Microsoft Sentinel workspace named Workspaces

You configure Workspace1 to collect DNS events and deploy the Advanced Security information Model (ASIM) unifying parser for the DNS schema.

You need to query the ASIM DNS schema to list all the DNS events from the last 24 hours that have a response code of 'NXDOMAIN' and were aggregated by the source IP address in 15-minute intervals.

The solution must maximize query performance.

How should you complete the query? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.


Question 155
Correct answer: Question 155
asked 05/10/2024
Subramaniam Pratheep
39 questions
User
0 comments
Sorted by

Leave a comment first