ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 259 - SC-200 discussion

Report
Export

You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1.

You create a hunting query that detects a new attack vector. The attack vector maps to a tactic listed in the MITRE ATT&CK database.

You need to ensure that an incident is created in WS1 when the new attack vector is detected.

What should you configure?

A.

a Fusion rule

Answers
A.

a Fusion rule

B.

a query bookmark

Answers
B.

a query bookmark

C.

a scheduled query rule

Answers
C.

a scheduled query rule

D.

a hunting livestream session

Answers
D.

a hunting livestream session

Suggested answer: C
asked 05/10/2024
Alvin Thomas
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first