DRAG DROP
-
You have a Microsoft Sentinel workspace named SW1.
In SW1, you enable User and Entity Behavior Analytics (UEBA).
You need to use KQL to perform the following tasks:
• View the entity data that has fields for each type of entity.
• Assess the quality of rules by analyzing how well a rule performs.
Which table should you use in KQL for each task? To answer, drag the appropriate tables to the correct tasks. Each table may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
DChilds
Highly Voted 11 months, 3 weeks agoCDR
4 months agoOptimizor_IT
Most Recent 3 days, 7 hours agog_man_rap
8 months ago