nerdexam
Microsoft

SC-200 · Question #231

You have a Microsoft Sentinel playbook that is triggered by using the Azure Activity connector. You need to create a new near-real-time (NRT) analytics rule that will use the playbook. What should…

The correct answer is B. the query rule. To create an NRT rule, you need to follow these steps: From the Microsoft Sentinel navigation menu, select Analytics. Select Create from the button bar, then NRT query rule (preview) from the drop-down list. Follow the instructions of the analytics rule wizard.

Submitted by jaden.t· Apr 18, 2026Detect and remediate threats using Microsoft Sentinel

Question

You have a Microsoft Sentinel playbook that is triggered by using the Azure Activity connector. You need to create a new near-real-time (NRT) analytics rule that will use the playbook. What should you configure for the rule?

Options

  • Athe incident automation settings
  • Bthe query rule
  • Centity mapping
  • Dthe Alert automation settings

How the community answered

(15 responses)
  • A
    7% (1)
  • B
    80% (12)
  • C
    13% (2)

Explanation

To create an NRT rule, you need to follow these steps: From the Microsoft Sentinel navigation menu, select Analytics. Select Create from the button bar, then NRT query rule (preview) from the drop-down list. Follow the instructions of the analytics rule wizard.

Topics

#Microsoft Sentinel#Analytics Rules#NRT Rules#Playbooks

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice