SC-200 · Question #231
You have a Microsoft Sentinel playbook that is triggered by using the Azure Activity connector. You need to create a new near-real-time (NRT) analytics rule that will use the playbook. What should…
The correct answer is B. the query rule. To create an NRT rule, you need to follow these steps: From the Microsoft Sentinel navigation menu, select Analytics. Select Create from the button bar, then NRT query rule (preview) from the drop-down list. Follow the instructions of the analytics rule wizard.
Question
You have a Microsoft Sentinel playbook that is triggered by using the Azure Activity connector. You need to create a new near-real-time (NRT) analytics rule that will use the playbook. What should you configure for the rule?
Options
- Athe incident automation settings
- Bthe query rule
- Centity mapping
- Dthe Alert automation settings
How the community answered
(15 responses)- A7% (1)
- B80% (12)
- C13% (2)
Explanation
To create an NRT rule, you need to follow these steps: From the Microsoft Sentinel navigation menu, select Analytics. Select Create from the button bar, then NRT query rule (preview) from the drop-down list. Follow the instructions of the analytics rule wizard.
Topics
Community Discussion
No community discussion yet for this question.