nerdexam
Microsoft

SC-200 · Question #317

You have a Microsoft Sentinel workspace named SW1. You need to identify which anomaly rules are enabled in SW1. What should you review in Microsoft Sentinel?

The correct answer is C. Analytics. In Microsoft Sentinel, the 'Analytics' blade is the central location to view and manage all types of detection rules, including anomaly rules, allowing users to identify which ones are enabled.

Submitted by mateo_ar· Apr 18, 2026

Question

You have a Microsoft Sentinel workspace named SW1. You need to identify which anomaly rules are enabled in SW1. What should you review in Microsoft Sentinel?

Options

  • AContent hub
  • BEntity behavior
  • CAnalytics
  • DSettings

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    82% (18)
  • D
    9% (2)

Why each option

In Microsoft Sentinel, the 'Analytics' blade is the central location to view and manage all types of detection rules, including anomaly rules, allowing users to identify which ones are enabled.

AContent hub
BEntity behavior
CAnalyticsCorrect

The 'Analytics' blade in Microsoft Sentinel is the central location where all detection rules, including anomaly rules, are managed. Users can review, enable, disable, and configure the settings for all their analytical rules from this section, making it the definitive place to identify which anomaly rules are enabled.

DSettings

The 'Settings' blade in Microsoft Sentinel is for workspace-level configurations and general preferences, not for the direct management or listing of enabled anomaly rules.

Concept tested: Microsoft Sentinel anomaly rule management

Source: https://learn.microsoft.com/en-us/azure/sentinel/get-started-anomaly-rules

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice