FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 2

Question 86

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have an Azure subscription that contains a virtual machine named VM1 and uses Microsoft Defender for Cloud. Microsoft Defender for Cloud has automatic provisioning configured to use Azure Monitor Agent. You need to create a custom alert suppression rule that will suppress false positive alerts for suspicious use of PowerShell on VM1. What should you do first?

  • AFrom Microsoft Defender for Cloud, export the alerts to a Log Analytics workspace.
  • BFrom Microsoft Defender for Cloud, add a workflow automation.
  • COn VM1, trigger a PowerShell alert. ✓
  • DOn VM1, run the Get-MPThreatCatalog cmdlet.