SC-200 Practice Question 3853

Exam: SC-200
Domain: Perform threat hunting
Difficulty: easy
In Microsoft Defender XDR Advanced Hunting, what action can an analyst take directly from a validated KQL query to automatically generate alerts on matching future events 24/7?

Answer Options

A
Click "Create custom detection rule" to execute queries on a schedule
B
Copy the query into a local Word document
C
Run the query manually every 5 minutes by hand
D
Save the query as an internet browser bookmark

Correct Answer

A: Click "Create custom detection rule" to execute queries on a schedule

Explanation

Click "Create custom detection rule" to configure an automated background job that executes the KQL query on a schedule, generates incidents, and triggers automatic remediation actions.