You are using Skope IT to analyze and correlate a security incident. You are seeing too many events generated by API policies. You want to filter for logs generated by the Netskope client only.
Based on the information provided, I think the domain partition is the one we need to modify. The Employee-Number attribute is likely stored in the domain partition, so that's where we should focus our efforts.
Hmm, I'm not totally sure about this one. I'll need to think through how an entity's approach to defending or settling suits could affect its overall loss experience. Might be worth reviewing my notes on this topic.
I'm with the majority on this one. Option A is the way to go. Though I do wonder if the exam writers threw in those other options just to trip us up. Sneaky, sneaky.
Hmm, I don't think 'Tunnel' or 'Logs' in the access_method filter would work here. We need to specifically target the Netskope client, and Option A looks like the clear winner.
Option A seems like the way to go. I mean, filtering for 'Client' in the access_method makes sense if we want to focus on the Netskope client events, right?
I'm not sure, but I think option D) Use query mode and use access_method neq Client could also work to filter out logs not generated by the Netskope client.
Raymon
4 months agoRoselle
5 months agoErasmo
5 months agoAlesia
5 months agoStacey
5 months agoLeslie
6 months agoDonte
6 months agoLaura
6 months agoBarbra
6 months agoAngelica
6 months agoSalome
6 months agoStephaine
6 months agoIsadora
6 months agoMarnie
6 months agoNakita
6 months agoMajor
6 months agoDewitt
6 months agoTu
6 months agoCarissa
12 months agoAndrew
11 months agoTresa
11 months agoRenea
11 months agoHaley
12 months agoKathryn
11 months agoGolda
11 months agoLashon
11 months agoCherilyn
11 months agoElliot
12 months agoZita
11 months agoAnastacia
11 months agoLaurene
1 year agoShawnda
11 months agoRessie
11 months agoDottie
11 months agoTammara
11 months agoTuyet
1 year agoVeronika
1 year agoMerissa
1 year ago