SC-200 Practice Question 3740

Exam: SC-200
Domain: Manage a security operations environment
Difficulty: medium
In Microsoft Defender XDR, where can an analyst configure custom detection rules that execute scheduled KQL queries and generate new incidents?

Answer Options

A
Under Advanced Hunting in the Microsoft Defender portal
B
In the local Windows Registry
C
In the BIOS management console
D
In public DNS record settings

Correct Answer

A: Under Advanced Hunting in the Microsoft Defender portal

Explanation

Under Advanced Hunting in the Microsoft Defender portal, select "Create custom detection rule" to execute queries on schedules ranging from 1 to 24 hours.