ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 143 - SC-200 discussion

Report
Export

You have a Microsoft Sentinel workspace.

You need to prevent a built-in Advance Security information Model (ASIM) parse from being updated automatically.

What are two ways to achieve this goal? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A.

Redeploy the built-in parse and specify a CallerContext parameter of any and a SourceSpecificParse parameter of any.

Answers
A.

Redeploy the built-in parse and specify a CallerContext parameter of any and a SourceSpecificParse parameter of any.

B.

Create a hunting query that references the built-in parse.

Answers
B.

Create a hunting query that references the built-in parse.

C.

Redeploy the built-in parse and specify a CallerContext parameter of built-in.

Answers
C.

Redeploy the built-in parse and specify a CallerContext parameter of built-in.

D.

Build a custom unify parse and include the build- parse version

Answers
D.

Build a custom unify parse and include the build- parse version

E.

Create an analytics rule that includes the built-in parse

Answers
E.

Create an analytics rule that includes the built-in parse

Suggested answer: A, D
asked 05/10/2024
Edwin Lebron
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first