ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 163 - SC-200 discussion

Report
Export

You have a Microsoft Sentinel workspace named Workspaces

You need to exclude a built-in. source-specific Advanced Security Information Model (ASIM) parser from a built-in unified ASIM parser.

What should you create in Workspace1?

A.

a workbook

Answers
A.

a workbook

B.

a hunting query

Answers
B.

a hunting query

C.

a watchlist

Answers
C.

a watchlist

D.

an analytic rule

Answers
D.

an analytic rule

Suggested answer: D

Explanation:

To exclude a built-in, source-specific Advanced Security Information Model (ASIM) parser from a built-in unified ASIM parser, you should create an analytic rule in the Microsoft Sentinel workspace.

An analytic rule allows you to customize the behavior of the unified ASIM parser and exclude specific source-specific parsers from being used. Reference:Ă‚ https://docs.microsoft.com/en-us/azure/sentinel/analytics-create-analytic-rule

asked 05/10/2024
Mark Singer
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first