SC-200 Respond to security incidents • Set 4
SC-200 Respond to security incidents Practice Test 4 — 15 questions with explanations. Free, no signup.
Your security operations center (SOC) uses Microsoft Sentinel with a custom analytics rule that generates an incident when more than 10 failed logons occur within 5 minutes. During a review, you notice that a single user triggered the rule by forgetting their password multiple times. The incident was automatically closed by a playbook. What is the most effective way to reduce false positives for this rule?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.