Câu 139: SC-200: Microsoft Security Operations Analyst
You have a Microsoft Sentinel workspace. You receive multiple alerts for failed sign-in attempts to an account. You identify that the alerts are false positives. You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements:• Ensure that fa…
Nội dung câu hỏi
You have a Microsoft Sentinel workspace. You receive multiple alerts for failed sign-in attempts to an account. You identify that the alerts are false positives. You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements:• Ensure that failed sign-in alerts are generated for other accounts.• Minimize administrative effortWhat should do?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Modify the analytics rule. — đáp án hiện tại
- B. Create a watchlist.
- C. Add an activity template to the entity behavior.
- D. Create an automation rule.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.