ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 144 - SC-200 discussion

Report
Export

You have a Microsoft Sentinel workspace.

You receive multiple alerts for failed sign in attempts to an account.

You identify that the alerts are false positives.

You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements.

• Ensure that failed sign-in alerts are generated for other accounts.

• Minimize administrative effort

What should do?

A.

Create an automation rule.

Answers
A.

Create an automation rule.

B.

Create a watchlist.

Answers
B.

Create a watchlist.

C.

Modify the analytics rule.

Answers
C.

Modify the analytics rule.

D.

Add an activity template to the entity behavior.

Answers
D.

Add an activity template to the entity behavior.

Suggested answer: A

Explanation:

An automation rule will allow you to specify which alerts should be suppressed, ensuring that failed sign-in alerts are generated for other accounts while minimizing administrative effort. To create an automation rule, navigate to the

Automation Rules page in the Microsoft Sentinel workspace and configure the rule parameters to suppress the false positive alerts.

asked 05/10/2024
Paramdeep Saini
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first