You are using Skope IT to analyze and correlate a security incident. You are seeing too many events generated by API policies. You want to filter for logs generated by the Netskope client only.
I'm with the majority on this one. Option A is the way to go. Though I do wonder if the exam writers threw in those other options just to trip us up. Sneaky, sneaky.
Hmm, I don't think 'Tunnel' or 'Logs' in the access_method filter would work here. We need to specifically target the Netskope client, and Option A looks like the clear winner.
Option A seems like the way to go. I mean, filtering for 'Client' in the access_method makes sense if we want to focus on the Netskope client events, right?
I'm not sure, but I think option D) Use query mode and use access_method neq Client could also work to filter out logs not generated by the Netskope client.
Carissa
1 months agoAndrew
20 days agoTresa
29 days agoRenea
1 months agoHaley
2 months agoKathryn
27 days agoGolda
28 days agoLashon
1 months agoCherilyn
1 months agoElliot
2 months agoZita
18 days agoAnastacia
23 days agoLaurene
2 months agoShawnda
1 months agoRessie
1 months agoDottie
1 months agoTammara
1 months agoTuyet
2 months agoVeronika
2 months agoMerissa
2 months ago