List of questions
Related questions
Question 144 - SC-200 discussion
You have a Microsoft Sentinel workspace.
You receive multiple alerts for failed sign in attempts to an account.
You identify that the alerts are false positives.
You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements.
• Ensure that failed sign-in alerts are generated for other accounts.
• Minimize administrative effort
What should do?
A.
Create an automation rule.
B.
Create a watchlist.
C.
Modify the analytics rule.
D.
Add an activity template to the entity behavior.
Your answer:
0 comments
Sorted by
Leave a comment first