exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 10 discussion

Actual exam question from Microsoft's SC-200
Question #: 10
Topic #: 3
[All SC-200 Questions]

You have a custom analytics rule to detect threats in Azure Sentinel.
You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED.
What is a possible cause of the issue?

  • A. There are connectivity issues between the data sources and Log Analytics.
  • B. The number of alerts exceeded 10,000 within two minutes.
  • C. The rule query takes too long to run and times out.
  • D. Permissions to one of the data sources of the rule query were modified.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PJR
Highly Voted 3 years, 11 months ago
D - https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom#issue-a-scheduled-rule-failed-to-execute-or-appears-with-auto-disabled-added-to-the-name
upvoted 18 times
g_man_rap
8 months ago
somebody checked this link? is nothing about AUTO DISABLED or permissions? please check
upvoted 3 times
...
...
subhuman
Highly Voted 3 years, 1 month ago
Selected Answer: D
Correct answer is D Permanent failure - rule auto-disable due to the following reasons The target workspace (on which the rule query operated) has been deleted. The target table (on which the rule query operated) has been deleted. Microsoft Sentinel had been removed from the target workspace. A function used by the rule query is no longer valid; it has been either modified or removed. Permissions to one of the data sources of the rule query were changed. One of the data sources of the rule query was deleted or disconnected.
upvoted 6 times
...
Avaris
Most Recent 3 months ago
Selected Answer: D
D https://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-analytics-rules?source=recommendations
upvoted 2 times
...
talosDevbot
7 months ago
Answer is D As per Microsoft's own documentation on troubleshooting analytics rules: A rule is never autodisabled due to a transient failure One of their examples of transient failure is "A rule query takes too long to run and times out." The only rules that are auto-disabled are queries that have permanent failure. List as an example of permanent failure is "Permissions to one of the data sources of the rule query were changed" Link: https://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-analytics-rules
upvoted 2 times
...
b9cf0e5
7 months, 3 weeks ago
C- In Microsoft Sentinel, if an analytics rule is automatically disabled and the rule name is prefixed with "AUTO DISABLED," it typically indicates that the query within the rule has failed repeatedly. One common cause of this issue is that the query takes too long to execute or times out, which can lead to the rule being automatically disabled to avoid consuming excessive resources.
upvoted 3 times
...
g_man_rap
8 months, 3 weeks ago
C. The rule query takes too long to run and times out: Explanation: This is a common reason for Azure Sentinel to automatically disable a custom analytics rule. If a query takes too long to execute (usually due to complexity or large data volumes), it can lead to performance issues. Azure Sentinel may automatically disable such a rule to prevent it from impacting the overall performance of the system. Relevance: This is the most likely cause of the rule being automatically disabled and the name being prefixed with "AUTO DISABLED."
upvoted 1 times
...
Avaris
10 months ago
Selected Answer: C
answer is C not D
upvoted 2 times
...
Sneekygeek
1 year ago
Selected Answer: D
A permanent failure occurs due to a change in the conditions that allow the rule to run, which without human intervention can't return to their former status. The following are some examples of failures that are classified as permanent: The target workspace (on which the rule query operated) was deleted. The target table (on which the rule query operated) was deleted. Microsoft Sentinel was removed from the target workspace. A function used by the rule query is no longer valid; it was either modified or removed. Permissions to one of the data sources of the rule query were changed (see example). One of the data sources of the rule query was deleted. https://learn.microsoft.com/en-us/azure/sentinel/troubleshoot-analytics-rules
upvoted 1 times
...
xoe123
1 year, 3 months ago
A function used by the rule query is no longer valid; it has been either modified or removed. Permanent failure - rule auto-disabled Correct. For Transient failure there are two reasons and both are listed A rule query takes too long to run and times out. Connectivity issues between data sources and Log Analytics, or between Log Analytics and Microsoft Sentinel. Any other new and unknown failure is considered transient.
upvoted 1 times
...
xoe123
1 year, 3 months ago
Option D. I think it is option D as both option A and C are for transient and question asked to pick one option. Also question says stopped while with transient failure it tries again to run the rule
upvoted 1 times
...
DCT
1 year, 3 months ago
Selected Answer: D
Correct D.
upvoted 1 times
...
chepeerick
1 year, 6 months ago
Correct
upvoted 1 times
...
mali1969
1 year, 7 months ago
Selected Answer: D
The possible cause of the issue is D. Permissions to one of the data sources of the rule query were modified. Option C is not correct because the rule query timeout does not cause a rule to be disabled. The default timeout for a rule query is 10 minutes, but it can be extended up to 60 minutes by using the query_timeout parameter in the advanced settings. If a query exceeds the timeout limit, it will fail and generate an error, but it will not disable the rule.
upvoted 1 times
...
donathon
1 year, 8 months ago
Selected Answer: D
https://learn.microsoft.com/en-us/azure/sentinel/detect-threats-custom#permanent-failure---rule-auto-disabled
upvoted 1 times
...
D_PaW
1 year, 11 months ago
Selected Answer: A
Correct: ACD Transient reasons: * A rule query takes too long to run and times out. * Connectivity issues between data sources and Log Analytics, or between Log Analytics and Microsoft Sentinel. * Any other new and unknown failure is considered transient. Permanent reasons: * The target workspace (on which the rule query operated) has been deleted. * The target table (on which the rule query operated) has been deleted. * Microsoft Sentinel had been removed from the target workspace. * A function used by the rule query is no longer valid; it has been either modified or removed. * Permissions to one of the data sources of the rule query were changed. * One of the data sources of the rule query was deleted. Source: https://learn.microsoft.com/en-us/azure/sentinel/detect-threats-custom#issue-a-scheduled-rule-failed-to-execute-or-appears-with-auto-disabled-added-to-the-name
upvoted 1 times
...
stromnessian
3 years, 2 months ago
Selected Answer: D
D is correct.
upvoted 1 times
...
Eltooth
3 years, 6 months ago
Correct answer - D. Permission change stopped rule from connecting.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago