nerdexam
Microsoft

SC-200 · Question #204

You have an Azure subscription that contains a Microsoft Sentinel workspace. The workspace contains a Microsoft Defender for Cloud data connector. You need to customize which details will be…

The correct answer is D. Create a scheduled query rule. To customize which details will be included when an alert is created for a specific event in Microsoft Sentinel, you can modify the properties of the Microsoft Defender for Cloud data https://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details

Submitted by renata2k· Apr 18, 2026Configure protections and detections

Question

You have an Azure subscription that contains a Microsoft Sentinel workspace. The workspace contains a Microsoft Defender for Cloud data connector. You need to customize which details will be included when an alert is created for a specific event. What should you do?

Options

  • AEnable User and Entity Behavior Analytics (UEBA).
  • BCreate a Data Collection Rule (DCR).
  • CModify the properties of the connector.
  • DCreate a scheduled query rule.

How the community answered

(36 responses)
  • A
    14% (5)
  • B
    3% (1)
  • C
    8% (3)
  • D
    75% (27)

Explanation

To customize which details will be included when an alert is created for a specific event in Microsoft Sentinel, you can modify the properties of the Microsoft Defender for Cloud data https://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details

Topics

#Microsoft Sentinel#Analytics Rules#Alert Customization#Detections

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice