SC-200 Respond to security incidents • Set 28
SC-200 Respond to security incidents Practice Test 28 — 15 questions with explanations. Free, no signup.
Refer to the exhibit. You have created an automation rule in Microsoft Sentinel with the above configuration. The playbook isolates the device and disables the user account. After enabling the rule, you notice that a low-severity incident containing an alert titled 'Ransomware Behavior' did NOT trigger the automation. What is the most likely reason?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.