nerdexam
Microsoft

SC-200 · Question #39

You have a custom analytics rule to detect threats in Azure Sentinel. You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED…

The correct answer is D. Permissions to one of the data sources of the rule query were modified. Permanent failure - rule auto-disable due to the following reasons The target workspace (on which the rule query operated) has been deleted. The target table (on which the rule query operated) has been deleted. Microsoft Sentinel had been removed from the target workspace. A…

Submitted by amina.ke· Apr 18, 2026Configure protections and detections

Question

You have a custom analytics rule to detect threats in Azure Sentinel. You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED. What is a possible cause of the issue?

Options

  • AThere are connectivity issues between the data sources and Log Analytics.
  • BThe number of alerts exceeded 10,000 within two minutes.
  • CThe rule query takes too long to run and times out.
  • DPermissions to one of the data sources of the rule query were modified.

How the community answered

(50 responses)
  • A
    12% (6)
  • B
    4% (2)
  • C
    6% (3)
  • D
    78% (39)

Explanation

Permanent failure - rule auto-disable due to the following reasons The target workspace (on which the rule query operated) has been deleted. The target table (on which the rule query operated) has been deleted. Microsoft Sentinel had been removed from the target workspace. A function used by the rule query is no longer valid; it has been either modified or removed. Permissions to one of the data sources of the rule query were changed. One of the data sources of the rule query was deleted or disconnected. https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom#issue-a-scheduled- rule-failed-to-execute-or-appears-with-auto-disabled-added-to-the-name

Topics

#Azure Sentinel#Analytics Rules#Troubleshooting#Permissions

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice