SC-200 · Question #71
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is A. Yes. As this kind of alert is generated by ASC, so we need the Microsoft incident creation rule to create incidents from ASC into sentinel. https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are configuring Azure Sentinel. You need to create an incident in Azure Sentinel when a sign-in to an Azure virtual machine from a malicious IP address is detected. Solution: You create a Microsoft incident creation rule for a data connector. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(40 responses)- A93% (37)
- B8% (3)
Explanation
As this kind of alert is generated by ASC, so we need the Microsoft incident creation rule to create incidents from ASC into sentinel. https://docs.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference
Topics
Community Discussion
No community discussion yet for this question.