SC-200 Practice Question 3740
Exam: SC-200
Domain: Manage a security operations environment
Difficulty: medium
In Microsoft Defender XDR, where can an analyst configure custom detection rules that execute scheduled KQL queries and generate new incidents?
Answer Options
A
Under Advanced Hunting in the Microsoft Defender portal
B
In the local Windows Registry
C
In the BIOS management console
D
In public DNS record settings
Correct Answer
A: Under Advanced Hunting in the Microsoft Defender portal
Explanation
Under Advanced Hunting in the Microsoft Defender portal, select "Create custom detection rule" to execute queries on schedules ranging from 1 to 24 hours.