CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 17: SC-200: Microsoft Security Operations Analyst

You have the following advanced hunting query in Microsoft 365 Defender. You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours. Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct s…

Nội dung câu hỏi

You have the following advanced hunting query in Microsoft 365 Defender. You need to receive an alert when any process disables System Restore on a device managed by Microsoft Defender during the last 24 hours. Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.

Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Create a detection rule. — đáp án hiện tại
  2. B. Create a suppression rule.
  3. C. Add | order by Timestamp to the query.
  4. D. Replace DeviceProcessEvents with DeviceNetworkEvents.
  5. E. Add DeviceId and ReportId to the output of the query. — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề