SC-200 · Question #131
You have a Microsoft Sentinel workspace. You receive multiple alerts for failed sign-in attempts to an account. You identify that the alerts are false positives. You need to prevent additional…
The correct answer is A. Create an automation rule. Two methods for avoiding false positives: Automation rules create exceptions without modifying analytics rules. Scheduled analytics rules modifications permit more detailed and permanent exceptions. https://learn.microsoft.com/en-us/azure/sentinel/false-positives
Question
You have a Microsoft Sentinel workspace. You receive multiple alerts for failed sign-in attempts to an account. You identify that the alerts are false positives. You need to prevent additional failed sign-in alerts from being generated for the account. The solution must meet the following requirements:
- Ensure that failed sign-in alerts are generated for other accounts.
- Minimize administrative effort
What should do?
Options
- ACreate an automation rule.
- BCreate a watchlist.
- CModify the analytics rule.
- DAdd an activity template to the entity behavior.
How the community answered
(69 responses)- A75% (52)
- B3% (2)
- C6% (4)
- D16% (11)
Explanation
Two methods for avoiding false positives: Automation rules create exceptions without modifying analytics rules. Scheduled analytics rules modifications permit more detailed and permanent exceptions. https://learn.microsoft.com/en-us/azure/sentinel/false-positives
Topics
Community Discussion
No community discussion yet for this question.