SC-200 · Question #95
You are configuring Microsoft Cloud App Security. You have a custom threat detection policy based on the IP address ranges of your company's United States-based offices. You receive many alerts…
The correct answer is A. Configure automatic data enrichment. B. Add the IP addresses to the corporate address range category. If you override the automatic detection of location for company IP address ranges, you can prevent the impossible travel alerts. And you need to define your corporate address ranges so that they are not seen as risky…
Question
You are configuring Microsoft Cloud App Security. You have a custom threat detection policy based on the IP address ranges of your company’s United States-based offices. You receive many alerts related to impossible travel and sign-ins from risky IP addresses. You determine that 99% of the alerts are legitimate sign-ins from your corporate offices. You need to prevent alerts for legitimate sign-ins from known locations. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- AConfigure automatic data enrichment.
- BAdd the IP addresses to the corporate address range category.
- CIncrease the sensitivity level of the impossible travel anomaly detection policy.
- DAdd the IP addresses to the other address range category and add a tag.
- ECreate an activity policy that has an exclusion for the IP addresses.
How the community answered
(24 responses)- A75% (18)
- C4% (1)
- D17% (4)
- E4% (1)
Explanation
If you override the automatic detection of location for company IP address ranges, you can prevent the impossible travel alerts. And you need to define your corporate address ranges so that they are not seen as risky. https://docs.microsoft.com/en-us/defender-cloud-apps/media/newipaddress-range.png https://docs.microsoft.com/en-us/cloud-app-security/ip-tags
Topics
Community Discussion
No community discussion yet for this question.