exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 63 discussion

Actual exam question from Microsoft's SC-200
Question #: 63
Topic #: 3
[All SC-200 Questions]

You have a Microsoft Sentinel workspace named Workspace1.

You need to exclude a built-in, source-specific Advanced Security Information Model (ASIM) parser from a built-in unified ASIM parser.

What should you create in Workspace1?

  • A. an analytic rule
  • B. a watchlist
  • C. a workbook
  • D. a hunting query
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 1 year, 9 months ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/sentinel/normalization-manage-parsers
upvoted 12 times
...
palito1980
Highly Voted 1 year, 9 months ago
Selected Answer: B
To support excluding built-in source-specific parsers, ASIM uses a watchlist. https://learn.microsoft.com/en-us/azure/sentinel/normalization-manage-parsers#set-up-your-workspace
upvoted 10 times
...
a_kto_to
Most Recent 1 week ago
Selected Answer: B
ChatGTP: ✅ Correct answer: B. a watchlist 🧾 Explanation: To exclude a built-in, source-specific ASIM parser from a unified ASIM parser in Microsoft Sentinel, the recommended approach is to: 👉 Use a Watchlist Microsoft Sentinel uses watchlists to provide custom inclusion/exclusion logic for various features, including ASIM parsers. You can create a watchlist that lists the parsers you want to exclude, and then reference that watchlist in custom ASIM logic or configurations.
upvoted 1 times
...
aks_exam
6 months ago
on exam 2024/April
upvoted 4 times
...
Murtuza
10 months, 1 week ago
To support excluding built-in source-specific parsers, ASIM uses a watchlist.
upvoted 2 times
...
chepeerick
11 months, 3 weeks ago
Correct Option
upvoted 1 times
...
chepeerick
1 year ago
Selected Answer: B
To support excluding built-in source-specific parsers, ASIM uses a watchlist. Deploy the watchlist to your Microsoft Sentinel workspace from the Microsoft Sentinel GitHub repository. To define source type for built-in and custom parsers, ASIM uses a watchlist. Deploy the watchlist to your Microsoft Sentinel workspace from the Microsoft Sentinel GitHub repository.
upvoted 1 times
...
JoeP1
1 year, 2 months ago
Selected Answer: B
Answer B To modify an existing, built-in source-specific parser: 1 Create a custom parser based on the original parser and add it to the built-in parser. 2 Add a record to the ASim Disabled Parsers watchlist. 3 Define the CallerContext value as Exclude<parser name>, where <parser name> is the name of the unifying parsers you want to exclude the parser from. 4 Define the SourceSpecificParser value Exclude<parser name>, where <parser name>is the name of the parser you want to exclude, without a version specifier. (From: https://learn.microsoft.com/en-us/azure/sentinel/normalization-manage-parsers)
upvoted 2 times
...
billo79152718
1 year, 4 months ago
Selected Answer: B
B. A watchlist
upvoted 1 times
...
altecer
1 year, 8 months ago
On exam 2-11-2023
upvoted 5 times
...
eddz25
1 year, 9 months ago
Selected Answer: A
A. an analytic rule An analytic rule allows you to specify the conditions under which data is collected and analyzed. By creating an analytic rule in Workspace1, you can exclude a built-in, source-specific ASIM parser from a built-in unified ASIM parser by specifying conditions that exclude the data generated by that parser. For example, you could create an analytic rule that filters out all events generated by the built-in, source-specific parser you want to exclude, by using the "where" clause, this way the unified parser will not process the events generated by that source-specific parser. While the other options (B, C, D) are useful for different purposes, but none of them can be used to exclude a specific parser from a unified parser.
upvoted 1 times
yoton
1 year, 8 months ago
To support excluding built-in source-specific parsers, ASIM uses a watchlist. Deploy the watchlist to your Microsoft Sentinel workspace from the Microsoft Sentinel GitHub repository. From one of the above links provided.
upvoted 5 times
789sv
1 year, 4 months ago
Correct - B
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago