SC-200 • Practice Test 7
Free SC-200 practice test — 10 questions with explanations. Set 7. No signup required.
A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect sign-ins from IP addresses known to be associated with a threat actor. The list of threat actor IPs is maintained in a custom Microsoft Sentinel watchlist and is updated daily. The analyst wants the rule to query the SigninLogs table and compare the IP address against this list. What is the most efficient way to reference the list in the KQL query?
Choose an answer to begin — your selection is scored in the full session.
10 questions · instant feedback and full explanations after every question.