List of questions
Related questions
Question 133 - SC-200 discussion
You have a Microsoft Sentinel workspace that contains the following incident.
Brute force attack against Azure Portal analytics rule has been triggered.
You need to identify the geolocation information that corresponds to the incident.
What should you do?
A.
From Overview, review the Potential malicious events map.
B.
From Incidents, review the details of the iPCustomEntity entity associated with the incident.
C.
From Incidents, review the details of the AccouncCuscomEntity entity associated with the incident.
D.
From Investigation, review insights on the incident entity.
Your answer:
0 comments
Sorted by
Leave a comment first