SC-200 Manage a security operations environment • Set 6
SC-200 Manage a security operations environment Practice Test 6 — 15 questions with explanations. Free, no signup.
The exhibit shows a KQL query used in a Microsoft Sentinel analytics rule. The rule is intended to detect brute-force attacks by identifying IP addresses that have more than 10 failed sign-ins (result code 50057) followed by a successful sign-in (result code 0) within an hour. However, the rule is not triggering alerts even though you are confident such patterns exist. What is the most likely issue?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.