SC-200 • Practice Exam 51
Free SC-200 practice exam — 20 questions with explanations. Set 51. No signup required.
Refer to the exhibit. An analyst is reviewing a custom detection rule in Microsoft Sentinel. The rule is triggering many false positives from legitimate remote desktop connections. What should the analyst do to reduce false positives while keeping detection of pass-the-hash attacks?
Choose an answer to begin — your selection is scored in the full session.
20 questions · instant feedback and full explanations after every question.