nerdexam
Microsoft

SC-200 · Question #114

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. No, this does not meet the goal. A hunting livestream in Azure Sentinel is an interactive, real-time tool that allows analysts to execute a KQL query and stream results as new data arrives - it is designed for active, analyst-driven threat hunting sessions. Livestreams do not…

Submitted by paula_co· Apr 18, 2026Detect and remediate threats using Microsoft Sentinel

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Azure Sentinel. You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected. Solution: You create a livestream from a query. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(44 responses)
  • A
    14% (6)
  • B
    86% (38)

Explanation

No, this does not meet the goal. A hunting livestream in Azure Sentinel is an interactive, real-time tool that allows analysts to execute a KQL query and stream results as new data arrives - it is designed for active, analyst-driven threat hunting sessions. Livestreams do not automatically generate alerts or create incidents. To automatically create an incident when a malicious IP sign-in to an Azure VM is detected, you need a Microsoft incident creation rule based on Microsoft Defender for Cloud, which already detects this threat and surfaces it as a Sentinel signal that triggers incident creation.

Topics

#Azure Sentinel#Livestream#Incident Creation#Detection Rules

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice