AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel • Set 13
AZ-500 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel Practice Test 13 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Sentinel for security operations. You need to create a custom analytics rule that triggers an incident when a user executes a suspicious PowerShell command on a Windows server. The logs are stored in the 'DeviceEvents' table from Microsoft Defender for Endpoint (now part of Microsoft Defender XDR). The rule should run every 5 minutes. Which scheduling frequency and query period should you configure?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.