nerdexam
Microsoft

SC-200 · Question #70

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. No, this does not meet the goal. A hunting bookmark is an analyst-facing tool used during manual threat hunting investigations to save and annotate interesting query results for later review or follow-up. Bookmarks do not trigger incident creation - they are static markers on…

Submitted by carter_n· Apr 18, 2026Detect and remediate threats using Microsoft Sentinel

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Azure Sentinel. You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected. Solution: You create a hunting bookmark. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(45 responses)
  • A
    24% (11)
  • B
    76% (34)

Explanation

No, this does not meet the goal. A hunting bookmark is an analyst-facing tool used during manual threat hunting investigations to save and annotate interesting query results for later review or follow-up. Bookmarks do not trigger incident creation - they are static markers on query results. To automatically create an incident when a malicious IP sign-in is detected, you need a Microsoft incident creation rule linked to Microsoft Defender for Cloud alerts (which already detects this threat pattern) - not a hunting bookmark.

Topics

#Azure Sentinel#Incident creation#Hunting bookmarks#Threat detection

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice