SC-200 • Practice Test 34
Free SC-200 practice test — 15 questions with explanations. Set 34. No signup required.
Your organization uses Microsoft Sentinel. A security analyst reports a high number of false positives from a scheduled analytics rule that detects anomalous sign-ins. The rule uses the 'UserAgent' field in the SigninLogs table. What is the best practice to reduce false positives while maintaining detection coverage?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.