ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 156 - SC-200 discussion

Report
Export

HOTSPOT

You have an Azure subscription that contains an Microsoft Sentinel workspace.

You need to create a hunting query using Kusto Query Language (KQL) that meets the following requirements:

• Identifies an anomalous number of changes to the rules of a network security group (NSG) made by the same security principal

• Automatically associates the security principal with an Microsoft Sentinel entity

How should you complete the query? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


Question 156
Correct answer: Question 156
asked 05/10/2024
Olanrewaju Abolanle
31 questions
User
0 comments
Sorted by

Leave a comment first