exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 60 discussion

Actual exam question from Microsoft's SC-200
Question #: 60
Topic #: 3
[All SC-200 Questions]

You have a Microsoft Sentinel workspace.

You need to prevent a built-in Advanced Security Information Model (ASIM) parser from being updated automatically.

What are two ways to achieve this goal? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

  • A. Create a hunting query that references the built-in parser.
  • B. Build a custom unifying parser and include the built-in parser version.
  • C. Redeploy the built-in parser and specify a CallerContext parameter of Any and a SourceSpecificParser parameter of Any.
  • D. Redeploy the built-in parser and specify a CallerContext parameter of Built-in.
  • E. Create an analytics rule that includes the built-in parser.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ACSC
Highly Voted 2 years, 2 months ago
Selected Answer: BC
https://learn.microsoft.com/en-us/azure/sentinel/normalization-manage-parsers https://learn.microsoft.com/en-us/azure/sentinel/normalization-manage-parsers#prevent-an-automated-update-of-a-built-in-parser
upvoted 18 times
...
MS_KoolaidMan
Highly Voted 1 year, 4 months ago
Selected Answer: BE
B and E are correct based on the SC-200 Practice Assessment from Microsoft B. Build a custom unifying parser and include the built-in parser version E. Create an analytics rule and include the built-in parser https://learn.microsoft.com/en-us/credentials/certifications/practice-assessments-for-microsoft-certifications https://learn.microsoft.com/en-us/credentials/certifications/exams/sc-200/practice/assessment?assessment-type=practice&assessmentId=59
upvoted 15 times
...
Avaris
Most Recent 3 months ago
Selected Answer: BC
the question is in the MS assessment test and it was b and c
upvoted 2 times
...
Tuitor01
4 months, 3 weeks ago
Selected Answer: BC
Exam practice says so, doc confirms. Logic ties it all up.
upvoted 4 times
...
choukou
5 months ago
Selected Answer: BC
B and C are correct.
upvoted 1 times
...
12369b6
5 months, 3 weeks ago
B. Build a custom unifying parser and include the built-in parser version. Explanation: By building a custom unifying parser and explicitly specifying the version of the built-in parser, you can prevent automatic updates from affecting your custom logic. This ensures that even if the built-in parser is updated in the background, your custom parser will continue to use the specified version. D. Redeploy the built-in parser and specify a CallerContext parameter of Built-in. Explanation: By redeploying the built-in parser with the CallerContext parameter set to Built-in, you can effectively lock it to a specific version and prevent automatic updates from overriding your changes. This method allows for more control over when and how updates are applied.
upvoted 1 times
Sparkletoss
5 months, 1 week ago
It is BC according to practise exam
upvoted 2 times
...
...
smanzana
9 months ago
B and E are correct
upvoted 1 times
...
Hawklx
10 months, 1 week ago
Selected Answer: BE
like MS_KoolaidMan said
upvoted 1 times
...
devop23
11 months, 2 weeks ago
Selected Answer: BE
Correct based on the SC-200 Practice Assessment from Microsoft.
upvoted 1 times
...
DChilds
1 year ago
Selected Answer: BE
On the Microsoft Practice assessments, the answers to the same question are B and E.
upvoted 3 times
...
Ramye
1 year, 1 month ago
Selected Answer: BE
Confirmed by Microsoft SC-200 Practice Assessment as @MS_KoolaidMan mentioned below https://learn.microsoft.com/en-us/credentials/certifications/exams/sc-200/practice/assessment?assessment-type=practice&assessmentId=59
upvoted 4 times
...
xxjanixxasd
1 year, 5 months ago
Why do i pay money for that services when the answer is wrong? I made the test exam from Microsoft. Correct Answers are: - Redeploy the built-in parser and specify a CallerContext value of Any and a SourceSpecificParser value of Any. - Create an analytics rule and include the built-in parser.
upvoted 2 times
...
bivekluitel_101
1 year, 5 months ago
BE is correct as per Microsoft Learn Practice Assessment
upvoted 4 times
Ziyeahhh
1 year, 1 month ago
I agree!
upvoted 1 times
...
...
chepeerick
1 year, 6 months ago
Correct Option
upvoted 1 times
...
billo79152718
1 year, 8 months ago
Selected Answer: BC
B and C is correct
upvoted 1 times
...
itsadel
1 year, 9 months ago
Selected Answer: BD
The correct answers are B and D. Option B: Building a custom unifying parser and including the built-in parser version will prevent the built-in parser from being updated automatically. This is because the custom unifying parser will use the built-in parser version that you specify, and not the latest version that is available in the Microsoft Sentinel repository. Option D: Redeploying the built-in parser and specifying a CallerContext parameter of Built-in will also prevent the built-in parser from being updated automatically. This is because the CallerContext parameter specifies that the parser should only be used for built-in sources. If the parser is updated, it will no longer be considered a built-in source, and the CallerContext parameter will prevent it from being used.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago