Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam SC-200 All Questions
Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Microsoft Certified: Security Operations Analyst Associate SC-200 Question # 18 Topic 3 Discussion

SC-200 Exam Topic 3 Question 18 Discussion:
Question #: 18
Topic #: 3

You have a Microsoft Sentinel workspace that has user and Entity Behavior Analytics (UEBA) enabled for Signin Logs.

You need to ensure that failed interactive sign-ins are detected.

The solution must minimize administrative effort.

What should you use?


A.

a scheduled alert query


B.

a UEBA activity template


C.

the Activity Log data connector


D.

a hunting query


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.