nerdexam
Microsoft

SC-200 · Question #435

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. All endpoint devices are onboarded to Microsoft Defender for Endpoint. You have an Azure subscription that contains a…

The correct answer is A. a custom detection rule. You can use Microsoft Defender XDR custom detection rules (which are built on KQL) to run Advanced Hunting queries on a scheduled basis, such as once an hour, to proactively detect threats. While automation rules in Microsoft Sentinel can trigger actions, the underlying…

Submitted by kwame.gh· Apr 18, 2026

Question

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. All endpoint devices are onboarded to Microsoft Defender for Endpoint. You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace1. All Microsoft Defender XDR events are ingested into Workspace1. You have a Microsoft Entra tenant. You create a KQL query named query1 that searches device logs for a known vulnerability. You need to ensure that query1 runs every hour. The solution must minimize administrative effort. What should you configure?

Options

  • Aa custom detection rule
  • Bautomated investigation and response (AIR)
  • Ca watchlist
  • Dan automation rule

How the community answered

(39 responses)
  • A
    72% (28)
  • B
    5% (2)
  • C
    15% (6)
  • D
    8% (3)

Explanation

You can use Microsoft Defender XDR custom detection rules (which are built on KQL) to run Advanced Hunting queries on a scheduled basis, such as once an hour, to proactively detect threats. While automation rules in Microsoft Sentinel can trigger actions, the underlying mechanism to schedule and run Advanced Hunting queries is through the custom detection rules feature within Defender XDR. https://learn.microsoft.com/en-us/defender-xdr/custom-detection-rules

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice