SC-200 Manage a security operations environment • Set 5
SC-200 Manage a security operations environment Practice Test 5 — 15 questions with explanations. Free, no signup.
Your SOC team uses Microsoft Sentinel. You receive a high volume of false positive incidents from a specific analytics rule. The rule uses a scheduled query that runs every 5 minutes. What is the most efficient way to reduce false positives without disabling the rule?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.