exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 2 question 62 discussion

Actual exam question from Microsoft's MS-500
Question #: 62
Topic #: 2
[All MS-500 Questions]

You have a Microsoft 365 E5 subscription and a Microsoft Sentinel workspace named Sentinel1.

You need to launch the Guided Investigation – Process Alerts notebook in Sentinel1.

What should you create first?

  • A. an Azure logic app
  • B. a Log Analytics workspace
  • C. an Azure Machine Learning workspace
  • D. a Kusto query
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
KarimaMaf
1 year, 10 months ago
o use Jupyter notebooks in Microsoft Sentinel, you must first have the right permissions, depending on your user role. While you can run Microsoft Sentinel notebooks in JupyterLab or Jupyter classic, in Microsoft Sentinel, notebooks are run on an Azure Machine Learning (Azure ML) platform. To run notebooks in Microsoft Sentinel, you must have appropriate access to both Microsoft Sentinel workspace and an Azure ML workspace.
upvoted 1 times
KarimaMaf
1 year, 10 months ago
C IS CORRECT
upvoted 1 times
KarimaMaf
1 year, 10 months ago
CASE THE LOG ANALYTICS WORKSPACE IS ALREADY DEPLOYED
upvoted 1 times
...
...
...
Maxx4
1 year, 10 months ago
Selected Answer: C
The answer is C. an Azure Machine Learning workspace. Microsoft Sentinel notebooks are run on an Azure Machine Learning (Azure ML) platform. To run notebooks in Microsoft Sentinel, you must have appropriate access to both Microsoft Sentinel workspace and an Azure ML workspace. So, the first thing you need to do is create an Azure ML workspace. Once you have created an Azure ML workspace, you can then launch the Guided Investigation – Process Alerts notebook in Sentinel1. The other options are incorrect. Option A, an Azure logic app, is incorrect because Azure logic apps are used to automate workflows, not to run notebooks. Option B, a Log Analytics workspace, is incorrect because Log Analytics workspaces are used to store and analyze data, not to run notebooks. Option D, a Kusto query, is incorrect because Kusto queries are used to query data in Log Analytics workspaces, not to run notebooks. Therefore, the correct answer is C. https://learn.microsoft.com/en-us/azure/sentinel/notebooks
upvoted 1 times
...
Brigg5
1 year, 11 months ago
C is correct. "Microsoft Sentinel, notebooks are run on an Azure Machine Learning (Azure ML) platform. To run notebooks in Microsoft Sentinel, you must have appropriate access to both Microsoft Sentinel workspace and an Azure ML workspace." https://learn.microsoft.com/en-us/azure/sentinel/notebooks#manage-access-to-microsoft-sentinel-notebooks
upvoted 1 times
...
TavoGC
1 year, 11 months ago
Answer seems to be correct according to this link https://learn.microsoft.com/en-us/azure/sentinel/notebooks While you can run Microsoft Sentinel notebooks in JupyterLab or Jupyter classic, in Microsoft Sentinel, notebooks are run on an Azure Machine Learning (Azure ML) platform. To run notebooks in Microsoft Sentinel, you must have appropriate access to both Microsoft Sentinel workspace and an Azure ML workspace.
upvoted 1 times
...
esabkov
2 years ago
Selected Answer: C
Seems like C is correct - https://www.youtube.com/watch?v=OWjXee8o04M, please ignore other comments.
upvoted 1 times
...
esabkov
2 years ago
Selected Answer: A
Seems like A is correct - https://www.youtube.com/watch?v=OWjXee8o04M
upvoted 1 times
...
esabkov
2 years ago
Seems like A is correct - https://www.youtube.com/watch?v=OWjXee8o04M
upvoted 1 times
...
Unicorn02
2 years, 1 month ago
Selected Answer: D
No real idea here.Other Dumps mention Kusto Query as correct. Could not find any real proof from Microsoft Sources that relate to this question.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago