SC-200 Practice Question 3822

Exam: SC-200
Domain: Perform threat hunting
Difficulty: hard
You want to monitor incoming event streams in near-real-time to be notified the exact moment a specific malicious registry key is modified on any server. Which Microsoft Sentinel hunting feature provides this active notification stream?

Answer Options

A
Microsoft Sentinel Livestream
B
Static scheduled analytics rules
C
Weekly CSV report export
D
Workbooks performance tab

Correct Answer

A: Microsoft Sentinel Livestream

Explanation

Sentinel Livestream uses reactive KQL queries to test event feeds in real time, alerting analysts via interactive session notifications as matching events arrive.