Câu 117: SC-200: Microsoft Security Operations Analyst
DRAG DROP -You have a Microsoft Sentinel workspace named workspace1 and an Azure virtual machine named VM1. You receive an alert for suspicious use of PowerShell on VM1. You need to investigate the incident, identify which event triggered the alert, and identify whether the following actions occurred on VM1 after the…
Nội dung câu hỏi
DRAG DROP -You have a Microsoft Sentinel workspace named workspace1 and an Azure virtual machine named VM1. You receive an alert for suspicious use of PowerShell on VM1. You need to investigate the incident, identify which event triggered the alert, and identify whether the following actions occurred on VM1 after the alert:The modification of local group memberships ✑ The purging of event logsWhich three actions should you perform in sequence in the Azure portal? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Select and Place:
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
-
A. Lựa chọn A bằng hình ảnh — đáp án hiện tại
https://github.com/Azure/Azure-Sentinel/wiki/Investigation-Insights---Overview
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.