ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 148 - SC-200 discussion

Report
Export

You have a Microsoft Sentinel workspace named Workspace1.

You need to exclude a built-in, source-specific Advanced Security information Model (ASIM) parse from a built-in unified ASIM parser.

What should you create in Workspace1?

A.

a watch list

Answers
A.

a watch list

B.

an analytic rule

Answers
B.

an analytic rule

C.

a hunting query

Answers
C.

a hunting query

D.

a workbook

Answers
D.

a workbook

Suggested answer: A
asked 05/10/2024
Pedro Pereira
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first