Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam SC-200 All Questions
Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Microsoft Certified: Security Operations Analyst Associate SC-200 Question # 30 Topic 4 Discussion

SC-200 Exam Topic 4 Question 30 Discussion:
Question #: 30
Topic #: 4

You have a Microsoft Sentinel workspace named Workspacel that contains a table named CommonSecurityLog. You ingest logs into CommonSecurityLog. CommonSecurityLog has an average log ingestion time of five minutes.

You need to create an analytics rule that has a lookback period of seven minutes and uses the data in the CommonSecurityLog table. The solution must meet the following requirements:

• Prevent the same event from being processed twice.

• Minimize the number of missed events due to log ingestion delays.

How should you complete the KQL query that defines the rule? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-200 Question 30


Get Premium SC-200 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.