Question: In Microsoft Sentinel, a Scheduled Query Rule generates Bookmarks and Incidents based on the results of the query. Explanation: Bookmarks: These are used to mark
In Microsoft Sentinel, a Scheduled Query Rule generates Bookmarks and Incidents based on the results of the query.
Explanation:
Bookmarks: These are used to mark specific events or findings in logs for further investigation.
Incidents: These are created based on the detection logic of the rule to notify about potential security issues.
Correct Answer:
Bookmarks and incidents
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
