i will go for B as well
A parser should not filter by time. The query which uses the parser will apply a time range.
https://learn.microsoft.com/en-us/azure/sentinel/normalization-develop-parsers
The key issue here is that parsers in Sentinel expect the raw data as input, not the formatted or sorted results of a query.The first thing you need to do is remove line 5, which is the sorting operation. This will ensure that the raw data is passed to the parser.
Therefore, the correct answer is A. Remove line 5.
In Microsoft Sentinel, parsing and normalizing happen at query time. https://learn.microsoft.com/en-us/azure/sentinel/normalization-parsers-overview
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.SC-200 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
PhoenixSlasher
Highly Voted 10 months agoherta
Highly Voted 10 months, 2 weeks agoHAjouz
Most Recent 3 months, 3 weeks agoACSC
10 months, 4 weeks ago