SC-200 · Question #114
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. No, this does not meet the goal. A hunting livestream in Azure Sentinel is an interactive, real-time tool that allows analysts to execute a KQL query and stream results as new data arrives - it is designed for active, analyst-driven threat hunting sessions. Livestreams do not…
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Azure Sentinel. You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected. Solution: You create a livestream from a query. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(44 responses)- A14% (6)
- B86% (38)
Explanation
No, this does not meet the goal. A hunting livestream in Azure Sentinel is an interactive, real-time tool that allows analysts to execute a KQL query and stream results as new data arrives - it is designed for active, analyst-driven threat hunting sessions. Livestreams do not automatically generate alerts or create incidents. To automatically create an incident when a malicious IP sign-in to an Azure VM is detected, you need a Microsoft incident creation rule based on Microsoft Defender for Cloud, which already detects this threat and surfaces it as a Sentinel signal that triggers incident creation.
Topics
Community Discussion
No community discussion yet for this question.