Enabling Analytics Rules in Sentinel

5 questions Pass: 70% +15 pts

Quiz covering Security Monitoring and Automation

Enabling Analytics Rules in Sentinel

5 questions | Pass: 70% | Earn 15 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which section in the Microsoft Sentinel portal allows you to manage and enable pre-built detection logic?

  2. 2

    When configuring a scheduled analytics rule, what is the purpose of the 'Query scheduling' setting?

  3. 3

    If you want to reduce 'alert fatigue' by grouping multiple alerts generated by the same rule into a single incident, which feature should you configure?

  4. 4

    What is the primary function of 'Entity Mapping' within an Analytics rule?

  5. 5

    You have a custom KQL query that detects brute-force attacks. You need the rule to trigger an alert ONLY if the same user fails to sign in more than 5 times within 10 minutes, but you want to avoid duplicate incidents for the same user within a 2-hour window. How should you configure the rule?