List of questions
Related questions
Question 143 - SC-200 discussion
You have a Microsoft Sentinel workspace.
You need to prevent a built-in Advance Security information Model (ASIM) parse from being updated automatically.
What are two ways to achieve this goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A.
Redeploy the built-in parse and specify a CallerContext parameter of any and a SourceSpecificParse parameter of any.
B.
Create a hunting query that references the built-in parse.
C.
Redeploy the built-in parse and specify a CallerContext parameter of built-in.
D.
Build a custom unify parse and include the build- parse version
E.
Create an analytics rule that includes the built-in parse
Your answer:
0 comments
Sorted by
Leave a comment first