exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 6 question 27 discussion

Actual exam question from Microsoft's SC-200
Question #: 27
Topic #: 6
[All SC-200 Questions]

You have a Microsoft Sentinel workspace.

You are investigating an incident that involves multiple alerts, events, and entities.

You need to create a bookmark for the investigation. The solution must minimize administrative effort.

Which settings should you use?

  • A. Incidents
  • B. Hunting
  • C. Content hub
  • D. Logs
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sapphire
Highly Voted 6 months, 4 weeks ago
Selected Answer: B
Hunting is correct answer. https://learn.microsoft.com/en-us/azure/sentinel/bookmarks#add-bookmarks-to-a-new-or-existing-incident
upvoted 9 times
extop_mr
4 months, 2 weeks ago
You are already investigating an incident involving multiple alerts, events, and entities, the context focuses on managing and organizing findings within the scope of that incident. In this case, the appropriate place to manage and create bookmarks for ongoing investigations would actually be Incidents (A).
upvoted 1 times
...
...
jamspurple
Most Recent 3 months ago
Selected Answer: D
To CREATE a bookmark you go to Threat Management > Hunting, when you run a hunting query you need to go to the LOGS pane to create the bookmark. So the answer is Logs. If you want to add bookmarks to a new or existing incident, this is done through the Hunting pane. But the question specifically asks how you create a bookmark. Full explanation here including screenshots of the Logs pane being used. https://learn.microsoft.com/en-us/azure/sentinel/bookmarks#add-a-bookmark
upvoted 3 times
Krayzr
1 week, 5 days ago
YOU PREACH ABOUT HUNTING AND SELECTED LOGS :?
upvoted 1 times
...
...
HAjouz
3 months, 1 week ago
Selected Answer: B
To Create a bookmark -> For Microsoft Sentinel in the Azure portal, under Threat management select Hunting.
upvoted 1 times
...
siheom
5 months, 2 weeks ago
Selected Answer: A
should be A
upvoted 2 times
...
CDR
5 months, 3 weeks ago
Selected Answer: D
Bookmarks are exclusively created and managed within the Logs section. Here's a summary to solidify this: Incidents: The Incidents section is for managing and investigating security incidents. It provides a consolidated view of alerts, entities, and related information. You can't create bookmarks here.   Hunting: The Hunting section is for proactively searching for threats using hunting queries. While you might discover interesting data during a hunting exercise, you still need to go to the Logs section to create a bookmark for the corresponding KQL query.   Logs: The Logs section (powered by Log Analytics) is where you write and run KQL queries against your security data. This is the only place where you can create and manage bookmarks.
upvoted 4 times
CDR
5 months, 3 weeks ago
With all that said, you can still bookmark in the hunting blade. Hunting bookmarks enable users to save, tag, annotate, share and investigate results from a Log Analytics query.
upvoted 1 times
...
...
firdaous9
6 months ago
Selected Answer: A
Use Hunting for proactive threat detection. Use Incidents for investigating and managing evidence for pre-aggregated alerts and related events.
upvoted 2 times
...
Krankenwagen
6 months, 1 week ago
Selected Answer: A
I would prefer A. Not B, because Hunting is more appropriate for pro-active searching for anomalies Inside the incident, go to the Investigate tab. "As you investigate the various alerts, events, and entities related to the incident, you can bookmark the key items that are important for your investigation."
upvoted 4 times
...
Itsmebigal
6 months, 1 week ago
Selected Answer: D
Per Azure What is it? Hunting bookmarks enable users to save, tag, annotate, share and investigate results from a Log Analytics query. How does it work? Select a hunting query from the Microsoft Sentinel hunting page and click "View query results" in hunting query details to view the results in Log Analytics. Use the check boxes to select one or more rows that contain the information you find interesting and click "Add bookmark". This preserves the data in the row for future reference.
upvoted 2 times
...
chirva
7 months ago
GPT4: Here’s why Hunting is the appropriate setting: Hunting: This is where you can run queries to proactively search for threats in your environment. When you find something suspicious or noteworthy during your hunting activities, you can create a bookmark to save the specific event or finding for further investigation or correlation with other data.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...