SC-200 · Question #39
You have a custom analytics rule to detect threats in Azure Sentinel. You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED…
The correct answer is D. Permissions to one of the data sources of the rule query were modified. Permanent failure - rule auto-disable due to the following reasons The target workspace (on which the rule query operated) has been deleted. The target table (on which the rule query operated) has been deleted. Microsoft Sentinel had been removed from the target workspace. A…
Question
You have a custom analytics rule to detect threats in Azure Sentinel. You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED. What is a possible cause of the issue?
Options
- AThere are connectivity issues between the data sources and Log Analytics.
- BThe number of alerts exceeded 10,000 within two minutes.
- CThe rule query takes too long to run and times out.
- DPermissions to one of the data sources of the rule query were modified.
How the community answered
(50 responses)- A12% (6)
- B4% (2)
- C6% (3)
- D78% (39)
Explanation
Permanent failure - rule auto-disable due to the following reasons The target workspace (on which the rule query operated) has been deleted. The target table (on which the rule query operated) has been deleted. Microsoft Sentinel had been removed from the target workspace. A function used by the rule query is no longer valid; it has been either modified or removed. Permissions to one of the data sources of the rule query were changed. One of the data sources of the rule query was deleted or disconnected. https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom#issue-a-scheduled- rule-failed-to-execute-or-appears-with-auto-disabled-added-to-the-name
Topics
Community Discussion
No community discussion yet for this question.