When creating a scheduled query rule in Azure Sentinel (Rule1), which language or query format defines the rule logic?
Choose an answer
Tap an option to check your answer.
Correct answer: a Kusto query.
Why this is the answer
Scheduled query rules in Azure Sentinel are built using Kusto Query Language (KQL). KQL is specifically designed for querying large datasets in Azure Data Explorer and Azure Monitor, which Azure Sentinel leverages for its log analytics capabilities. This allows for powerful and flexible detection logic based on your ingested security logs. Transact-SQL is used for relational databases, not for log analytics in Azure Sentinel. A JSON definition might be used for rule configuration but not for the query logic itself. GraphQL is a query language for APIs, not for log data in this context.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed