SC-200 • Practice Test 38
Free SC-200 practice test — 15 questions with explanations. Set 38. No signup required.
During a threat hunting exercise in Microsoft Sentinel, you want to identify all cloud application events where a user accessed a resource from an IP address not previously associated with that user. Which KQL operator should you use to compare current access patterns with a baseline of known IPs?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.