SC-200 Perform threat hunting • Set 7
SC-200 Perform threat hunting Practice Test 7 — 15 questions with explanations. Free, no signup.
During a threat hunting exercise in Microsoft Sentinel, you want to identify all cloud application events where a user accessed a resource from an IP address not previously associated with that user. Which KQL operator should you use to compare current access patterns with a baseline of known IPs?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.