exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 32 discussion

Actual exam question from Microsoft's SC-200
Question #: 32
Topic #: 3
[All SC-200 Questions]

You create a hunting query in Azure Sentinel.
You need to receive a notification in the Azure portal as soon as the hunting query detects a match on the query. The solution must minimize effort.
What should you use?

  • A. a playbook
  • B. a notebook
  • C. a livestream
  • D. a bookmark
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
LiamNg
Highly Voted 2 years, 10 months ago
Because livestream notifications for new events use Azure portal notifications, you see these notifications whenever you use the Azure portal. Ref https://docs.microsoft.com/en-us/azure/sentinel/livestream#receive-notifications-when-new-events-occur
upvoted 19 times
...
stromnessian
Highly Voted 2 years, 6 months ago
Selected Answer: C
Aye, C.
upvoted 6 times
IxlJustinlxl
7 months ago
said the blind man to the deaf man.
upvoted 6 times
...
...
Onimole
Most Recent 5 days, 9 hours ago
Selected Answer: C
Receive notifications when new events occur Livestream notifications for new events appear with the Azure or Defender portal notifications. For example: Azure portal notification for livestream In the Azure or Defender portal, go to the notifications on the top right-hand side of the portal page. Select the notification to open the Livestream pane.
upvoted 1 times
...
DChilds
5 months, 1 week ago
Selected Answer: A
Playbooks are automated responses to alerts, and they can be configured to perform actions like sending notifications when a specific condition, such as a hunting query match, is met. Livestreams do not inherently send notifications; they are more about continuous monitoring and observation within the Azure Sentinel portal.
upvoted 5 times
CDR
2 months, 4 weeks ago
C. a livestream: Livestreaming in Log Analytics allows you to view logs in real-time, but it doesn't provide automated notifications. You would have to constantly monitor the livestream yourself.
upvoted 1 times
CDR
2 months, 4 weeks ago
So the answer is A. Playbook
upvoted 1 times
...
...
...
shimon893
6 months, 3 weeks ago
Selected Answer: C
it is in labs
upvoted 1 times
...
Pasapugazh
9 months, 1 week ago
Ans is Correct. Use hunting livestream to create interactive sessions that let you test newly created queries as events occur, get notifications from the sessions when a match is found, and launch investigations if necessary. https://learn.microsoft.com/en-us/azure/sentinel/livestream
upvoted 1 times
...
chepeerick
10 months, 3 weeks ago
Correct option
upvoted 1 times
...
itsadel
1 year, 2 months ago
Selected Answer: A
A livestream is a continuous stream of data that is sent to Azure Sentinel. Livestreams are not designed to send notifications. A playbook is a set of automated tasks that can be triggered by an alert or incident. In this case, you would create a playbook that sends a notification to the Azure portal as soon as the hunting query detects a match on the query.
upvoted 1 times
Durden871
5 months, 3 weeks ago
Wat? "Use hunting livestream to create interactive sessions that let you test newly created queries as events occur, get notifications from the sessions when a match is found, and launch investigations if necessary. " https://learn.microsoft.com/en-us/azure/sentinel/livestream
upvoted 2 times
...
...
7c0a
1 year, 2 months ago
Selected Answer: C
C - least effort, select hunting query, one click - add to livestream (three dots) or from the livestream tab add query, playbook also valid, but more clicks...
upvoted 1 times
...
stone7026
1 year, 2 months ago
is Azure Sentinel covered in PL200 actually?
upvoted 1 times
...
D_PaW
1 year, 3 months ago
Selected Answer: C
Least effort... start livestream, attach hunting query
upvoted 1 times
...
mansamusa
1 year, 5 months ago
Selected Answer: A
Answer is A
upvoted 2 times
...
[Removed]
1 year, 6 months ago
Selected Answer: A
a livestream cannot be used to receive a notification in the Azure portal as soon as a hunting query detects a match. Livestreams are used to stream security data from a security solution to Azure Sentinel in real-time. To receive a notification in the Azure portal as soon as a hunting query detects a match, you should use a playbook. You can create a playbook that includes a "Send email" or "Send a notification to Azure Monitor" action, and associate the playbook with the hunting query. When the hunting query detects a match, the playbook will trigger the email or notification action, and you will receive an alert in near real-time.
upvoted 4 times
wsrudmen
1 year, 6 months ago
This account "exmITQS" is really strange to provide so many bad answers witha lot of confusing explanations. Warning...
upvoted 19 times
...
...
liberty123
2 years, 7 months ago
Selected Answer: C
Livestream
upvoted 4 times
...
CaracasCCS1
2 years, 11 months ago
Correct.
upvoted 3 times
...
Eltooth
2 years, 11 months ago
Correct - C. Livestream
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago