ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 261 - SC-200 discussion

Report
Export

HOTSPOT

You have an Azure subscription that contains the following resources:

* A virtual machine named VM1 that runs Windows Server

* A Microsoft Sentinel workspace named Sentinel1 that has User and Entity Behavior Analytics (UEBA) enabled

You have a scheduled query rule named Rule1 that tracks sign-in attempts to VM1.

You need to update Rule 1 to detect when a user from outside the IT department of your company signs in to VM1. The solution must meet the following requirements:

* Utilize UEBA results.

* Maximize query performance.

* Minimize the number of false positives.

How should you complete the rule definition? To answer select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 261
Correct answer: Question 261
asked 05/10/2024
Kelvin Galabuzi
37 questions
User
0 comments
Sorted by

Leave a comment first