SC-200 Practice Question 3822
Exam: SC-200
Domain: Perform threat hunting
Difficulty: hard
You want to monitor incoming event streams in near-real-time to be notified the exact moment a specific malicious registry key is modified on any server. Which Microsoft Sentinel hunting feature provides this active notification stream?
Answer Options
A
Microsoft Sentinel Livestream
B
Static scheduled analytics rules
C
Weekly CSV report export
D
Workbooks performance tab
Correct Answer
A: Microsoft Sentinel Livestream
Explanation
Sentinel Livestream uses reactive KQL queries to test event feeds in real time, alerting analysts via interactive session notifications as matching events arrive.