SC-200 Practice Question 3853
Exam: SC-200
Domain: Perform threat hunting
Difficulty: easy
In Microsoft Defender XDR Advanced Hunting, what action can an analyst take directly from a validated KQL query to automatically generate alerts on matching future events 24/7?
Answer Options
A
Click "Create custom detection rule" to execute queries on a schedule
B
Copy the query into a local Word document
C
Run the query manually every 5 minutes by hand
D
Save the query as an internet browser bookmark
Correct Answer
A: Click "Create custom detection rule" to execute queries on a schedule
Explanation
Click "Create custom detection rule" to configure an automated background job that executes the KQL query on a schedule, generates incidents, and triggers automatic remediation actions.