ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 254 - SC-200 discussion

Report
Export

DRAG DROP

You have a Microsoft Sentinel workspace that contains the following Advanced Security Information Model (ASIM) parsers:

* _Im_ProcessCreate

* InProceessCreate

You create a new source-specific parser named vimProcessCreate.

You need to modify the parsers to meet the following requirements:

* Call all the ProcessCreate parsers.

* Standardize fields to the Process schema.

Which parser should you modify to meet each requirement? To answer, drag the appropriate parsers to the correct requirements. tach parser may be used once, more than once, or not at all You may need to drag the split bar between panes or scroll to view content.

NOTE Each correct selection is worth one point.


Question 254
Correct answer: Question 254
asked 05/10/2024
Arkadiusz Skopinski
40 questions
User
0 comments
Sorted by

Leave a comment first