You are using Skope IT to analyze and correlate a security incident. You are seeing too many events generated by API policies. You want to filter for logs generated by the Netskope client only.
Based on the information provided, I think the domain partition is the one we need to modify. The Employee-Number attribute is likely stored in the domain partition, so that's where we should focus our efforts.
Hmm, I'm not totally sure about this one. I'll need to think through how an entity's approach to defending or settling suits could affect its overall loss experience. Might be worth reviewing my notes on this topic.
I'm with the majority on this one. Option A is the way to go. Though I do wonder if the exam writers threw in those other options just to trip us up. Sneaky, sneaky.
Hmm, I don't think 'Tunnel' or 'Logs' in the access_method filter would work here. We need to specifically target the Netskope client, and Option A looks like the clear winner.
Option A seems like the way to go. I mean, filtering for 'Client' in the access_method makes sense if we want to focus on the Netskope client events, right?
I'm not sure, but I think option D) Use query mode and use access_method neq Client could also work to filter out logs not generated by the Netskope client.
Raymon
3 months agoRoselle
3 months agoErasmo
3 months agoAlesia
4 months agoStacey
4 months agoLeslie
4 months agoDonte
4 months agoLaura
4 months agoBarbra
5 months agoAngelica
5 months agoSalome
5 months agoStephaine
5 months agoIsadora
5 months agoMarnie
5 months agoNakita
5 months agoMajor
5 months agoDewitt
5 months agoTu
5 months agoCarissa
10 months agoAndrew
9 months agoTresa
10 months agoRenea
10 months agoHaley
10 months agoKathryn
9 months agoGolda
10 months agoLashon
10 months agoCherilyn
10 months agoElliot
10 months agoZita
9 months agoAnastacia
9 months agoLaurene
11 months agoShawnda
10 months agoRessie
10 months agoDottie
10 months agoTammara
10 months agoTuyet
11 months agoVeronika
11 months agoMerissa
11 months ago