List of questions
Related questions
Question 148 - SC-200 discussion
You have a Microsoft Sentinel workspace named Workspace1.
You need to exclude a built-in, source-specific Advanced Security information Model (ASIM) parse from a built-in unified ASIM parser.
What should you create in Workspace1?
A.
a watch list
B.
an analytic rule
C.
a hunting query
D.
a workbook
Your answer:
0 comments
Sorted by
Leave a comment first