Practice Test Geeks home

SC-200 Threat Detection & Monitoring 3

Which KQL operator would you use in Microsoft Sentinel to join the SecurityAlert table with the IdentityInfo table to enrich alerts with user department information?

Select your answer
SC-200 Threat Detection & Monitoring 3 Quiz 2026 September