What is a possible cause of the issue?

You have a custom analytics rule to detect threats in Azure Sentinel.

You discover that the analytics rule stopped running. The rule was disabled, and the rule name has a prefix of AUTO DISABLED.

What is a possible cause of the issue?
A . There are connectivity issues between the data sources and Log Analytics.
B . The number of alerts exceeded 10,000 within two minutes.
C . The rule query takes too long to run and times out.
D . Permissions to one of the data sources of the rule query were modified.

Answer: D

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

Latest SC-200 Practice Questions with 75 Q&As

Updated Study Material | Instant Download | Detailed Answers and Explanations

Subscribe
Notify of
guest
0 Comments