Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft Exam SC-200 Topic 4 Question 64 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 64
Topic #: 4
[All SC-200 Questions]

You have a Microsoft Sentinel playbook that is triggered by using the Azure Activity connector.

You need to create a new near-real-time (NRT) analytics rule that will use the playbook.

What should you configure for the rule?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Anastacia
8 months ago
That's a good point, Glory. But I think the question is asking specifically about what we need to configure for the rule itself, not the playbook. So I still think C) the query rule is the best answer.
upvoted 0 times
...
Glory
8 months ago
Hmm, I'm not so sure. What about the Incident automation settings? Couldn't that be a valid option since the playbook is being triggered by the Azure Activity connector?
upvoted 0 times
...
Honey
8 months ago
I agree with Candida. The question specifically states that we need to create a new NRT analytics rule, so the query rule is the logical choice here.
upvoted 0 times
...
Candida
8 months ago
Hmm, that's an interesting thought, David. But I still think the query rule is the most important thing to configure for a new NRT analytics rule. The other settings are more about what happens after the rule is triggered.
upvoted 0 times
Earlean
7 months ago
G: the Alert automation settings
upvoted 0 times
...
Johnetta
8 months ago
F: Definitely, without the right query rule, the playbook won't be effective.
upvoted 0 times
...
Jean
8 months ago
E: the query rule
upvoted 0 times
...
Alfreda
8 months ago
D: I think the query rule is the key to making the playbook work efficiently.
upvoted 0 times
...
Casie
8 months ago
C: the Incident automation settings
upvoted 0 times
...
Yan
8 months ago
B: Yes, I agree. The query rule is essential for the new NRT analytics rule.
upvoted 0 times
...
Roxane
8 months ago
A: the query rule
upvoted 0 times
...
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77