You are using Skope IT to analyze and correlate a security incident. You are seeing too many events generated by API policies. You want to filter for logs generated by the Netskope client only.
Based on the information provided, I think the domain partition is the one we need to modify. The Employee-Number attribute is likely stored in the domain partition, so that's where we should focus our efforts.
Hmm, I'm not totally sure about this one. I'll need to think through how an entity's approach to defending or settling suits could affect its overall loss experience. Might be worth reviewing my notes on this topic.
I'm with the majority on this one. Option A is the way to go. Though I do wonder if the exam writers threw in those other options just to trip us up. Sneaky, sneaky.
Hmm, I don't think 'Tunnel' or 'Logs' in the access_method filter would work here. We need to specifically target the Netskope client, and Option A looks like the clear winner.
Option A seems like the way to go. I mean, filtering for 'Client' in the access_method makes sense if we want to focus on the Netskope client events, right?
I'm not sure, but I think option D) Use query mode and use access_method neq Client could also work to filter out logs not generated by the Netskope client.
Raymon
6 months agoRoselle
6 months agoErasmo
6 months agoAlesia
7 months agoStacey
7 months agoLeslie
7 months agoDonte
7 months agoLaura
7 months agoBarbra
8 months agoAngelica
8 months agoSalome
8 months agoStephaine
8 months agoIsadora
8 months agoMarnie
8 months agoNakita
8 months agoMajor
8 months agoDewitt
8 months agoTu
8 months agoCarissa
1 year agoAndrew
1 year agoTresa
1 year agoRenea
1 year agoHaley
1 year agoKathryn
1 year agoGolda
1 year agoLashon
1 year agoCherilyn
1 year agoElliot
1 year agoZita
1 year agoAnastacia
1 year agoLaurene
1 year agoShawnda
1 year agoRessie
1 year agoDottie
1 year agoTammara
1 year agoTuyet
1 year agoVeronika
1 year agoMerissa
1 year ago