ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 165 - SC-200 discussion

Report
Export

You provision Azure Sentinel for a new Azure subscription.

You are configuring the Security Events connector.

While creating a new rule from a template in the connector, you decide to generate a new alert for every event.

You create the following rule query.

By which two components can you group alerts into incidents? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A.

a workbook

Answers
A.

a workbook

B.

a hunting query

Answers
B.

a hunting query

C.

a notebook

Answers
C.

a notebook

D.

a playbook

Answers
D.

a playbook

Suggested answer: A

Explanation:

A workbook is a data-driven interactive report in Microsoft Sentinel. You can use workbooks to create custom reports based on data from your Azure subscription. Reference:

https://docs.microsoft.com/en-us/azure/sentinel/workbooks-overview

asked 05/10/2024
Cintron, Rigoberto
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first