SC-200 Manage a security operations environment • Set 18
SC-200 Manage a security operations environment Practice Test 18 — 15 questions with explanations. Free, no signup.
You are a security operations engineer for a company that uses Microsoft Defender XDR. You need to create a custom detection rule that alerts when a user performs more than 10 failed logon attempts within 5 minutes from different IP addresses. The rule should use the IdentityLogonEvents table. You have written the KQL query and now need to configure the rule settings in Microsoft 365 Defender. Which configuration should you use for the rule frequency and lookback period to minimize false positives while ensuring timely detection?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.