SC-200 · Question #317
You have a Microsoft Sentinel workspace named SW1. You need to identify which anomaly rules are enabled in SW1. What should you review in Microsoft Sentinel?
The correct answer is C. Analytics. In Microsoft Sentinel, the 'Analytics' blade is the central location to view and manage all types of detection rules, including anomaly rules, allowing users to identify which ones are enabled.
Question
You have a Microsoft Sentinel workspace named SW1. You need to identify which anomaly rules are enabled in SW1. What should you review in Microsoft Sentinel?
Options
- AContent hub
- BEntity behavior
- CAnalytics
- DSettings
How the community answered
(22 responses)- A5% (1)
- B5% (1)
- C82% (18)
- D9% (2)
Why each option
In Microsoft Sentinel, the 'Analytics' blade is the central location to view and manage all types of detection rules, including anomaly rules, allowing users to identify which ones are enabled.
The 'Analytics' blade in Microsoft Sentinel is the central location where all detection rules, including anomaly rules, are managed. Users can review, enable, disable, and configure the settings for all their analytical rules from this section, making it the definitive place to identify which anomaly rules are enabled.
The 'Settings' blade in Microsoft Sentinel is for workspace-level configurations and general preferences, not for the direct management or listing of enabled anomaly rules.
Concept tested: Microsoft Sentinel anomaly rule management
Source: https://learn.microsoft.com/en-us/azure/sentinel/get-started-anomaly-rules
Community Discussion
No community discussion yet for this question.