An analyst’s on-demand hunting query found repeatable unusual Key Vault access from a new ASN against lock-lab vaults. What should the Azure security engineer do so the pattern pages the SOC going forward?
Select an answer to reveal the explanation.
Short Explanation
A hunting query is a flashlight, not a pager. Promote that Key Vault ASN pattern into a scheduled analytics rule so Sentinel starts filing incidents when it shows up again.
Full Explanation
Hunting queries are on-demand investigations; they do not by themselves page the SOC. When a repeatable malicious or suspicious pattern is confirmed, the Azure security engineer promotes or creates a scheduled analytics rule so future matches create incidents. Security Copilot substitution and disabling diagnostics work against detection goals. This item stays at AZ-500 enable-and-configure depth, not an SC-200 hunting-notebook specialty.