200-201 • Practice Test 43
Free 200-201 practice test — 15 questions with explanations. Set 43. No signup required.
A SOC team is evaluating a SIEM rule that triggers on 'more than 10 failed login attempts from a single source within 5 minutes.' The rule is generating too many alerts from a legitimate external monitoring service. How should the rule be modified?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.