Microsoft SC-900 Microsoft Security, Compliance, and Identity Fundamentals Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A security analyst is tasked with configuring Microsoft Sentinel to enhance threat detection capabilities for a financial institution. The analyst needs to set up a custom analytics rule that triggers alerts based on specific patterns of user behavior indicative of potential insider threats. The rule should analyze user login patterns, focusing on unusual login times and locations. Which approach should the analyst take to effectively implement this custom analytics rule in Microsoft Sentinel?

Create a scheduled query rule that uses Kusto Query Language (KQL) to analyze the sign-in logs for anomalies in login times and geolocations, and set thresholds for alerting based on historical data patterns.
Utilize built-in machine learning models to automatically detect anomalies in user behavior without any custom configuration.
Implement a basic alert rule that triggers on any failed login attempts, regardless of the context or user behavior.
Set up a manual review process for all user logins, requiring security personnel to analyze each login attempt individually.

About the Microsoft SC-900 Microsoft Security, Compliance, and Identity Fundamentals Certification

These free practice questions are designed to help you assess your readiness for the Microsoft SC-900 Microsoft Security, Compliance, and Identity Fundamentals exam by Microsoft. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.