exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 67 discussion

Actual exam question from Microsoft's SC-200
Question #: 67
Topic #: 3
[All SC-200 Questions]

You have an Azure subscription that contains a Microsoft Sentinel workspace. The workspace contains a Microsoft Defender for Cloud data connector.

You need to customize which details will be included when an alert is created for a specific event.

What should you do?

  • A. Enable User and Entity Behavior Analytics (UEBA).
  • B. Create a Data Collection Rule (DCR).
  • C. Modify the properties of the connector.
  • D. Create a scheduled query rule.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
smosmo
Highly Voted 1 year, 8 months ago
Selected Answer: D
D is correct: https://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details
upvoted 9 times
...
a_kto_to
Most Recent 1 week ago
Selected Answer: D
ChatGTP: ✅ Correct answer: D. Create a scheduled query rule 🧾 Explanation: To customize which details are included when an alert is created in Microsoft Sentinel for a specific event, the correct approach is to: 👉 Create a scheduled query rule Scheduled query rules in Sentinel allow you to: Write a custom KQL query to detect specific events or patterns. Define custom alert details, including alert name, severity, entities, and description. Customize the output and enrichment of the alert. This gives you full control over what data gets included in the alert based on the results of the query.
upvoted 1 times
...
LinearB
3 months ago
Selected Answer: C
To customize which details will be included when an alert is created for a specific event in Microsoft Sentinel, you should C. Modify the properties of the connector. By modifying the properties of the Microsoft Defender for Cloud data connector, you can specify which details and fields are included in the alert. https://learn.microsoft.com/en-us/azure/sentinel/customize-alert-details?tabs=azure
upvoted 1 times
...
kazaki
8 months, 1 week ago
Selected Answer: B
data collector from defender for cloud
upvoted 1 times
...
chepeerick
11 months, 3 weeks ago
Correct option
upvoted 1 times
...
chepeerick
1 year ago
Selected Answer: C
select the "Data connectors" option.
upvoted 1 times
...
billo79152718
1 year, 2 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
itsadel
1 year, 3 months ago
Selected Answer: B
The answer is B. Create a Data Collection Rule (DCR). A Data Collection Rule (DCR) is a way to customize which details will be included when an alert is created for a specific event. You can use a DCR to specify the fields that you want to include in the alert, as well as the format of the alert.
upvoted 2 times
kabooze
11 months, 3 weeks ago
No, DCR is to customize which logs you ingest. Not what is included in the alert. 2 separate things.
upvoted 1 times
Discuss4certi
8 months ago
Agree, DCR decides which logs remain in the sentinel. A query can decide which tables aka details are displayed
upvoted 1 times
...
...
...
7c0a
1 year, 3 months ago
Selected Answer: D
A & B are obviously not relevant C - might be true for some data connectors, but this one Defender for Cloud does not provide any filtering options D - correct one, https://learn.microsoft.com/en-us/azure/sentinel/connect-defender-for-cloud
upvoted 4 times
...
[Removed]
1 year, 7 months ago
Selected Answer: C
o customize which details will be included when an alert is created for a specific event in Microsoft Sentinel for a Microsoft Defender for Cloud data connector, you should modify the properties of the connector. Therefore, the correct answer is C. Modify the properties of the connector.
upvoted 1 times
piliblu
1 year, 5 months ago
this guy gives very weird answers, must are wrong! warning
upvoted 12 times
...
evilprime
1 year, 6 months ago
this is a chatgpt answer, and i think he's (she?) is wrong here. I think the right answer is D.
upvoted 8 times
...
...
antoniokt
1 year, 7 months ago
Selected Answer: D
D is correct
upvoted 4 times
...
[Removed]
1 year, 7 months ago
Selected Answer: C
C. Modify the properties of the connector. To customize which details will be included when an alert is created for a specific event in Microsoft Sentinel, you can modify the properties of the Microsoft Defender for Cloud data connector.
upvoted 1 times
...
watoz1851
1 year, 8 months ago
Select a scheduled query rule and select Edit. Or create a new rule by selecting Create > Scheduled query rule at the top of the screen.
upvoted 2 times
...
PhoenixSlasher
1 year, 8 months ago
Selected Answer: D
I would say this is the entities it is referring to which is configurable through analytic rules
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago