[Detection Engineering]
A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)
[Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]
Lacresha
2 months agoAracelis
2 months agoEmeline
3 months agoSolange
3 months agoDorthy
3 months agoKirk
3 months agoLatricia
4 months agoLuther
4 months agoKati
4 months agoLashaun
4 months agoSharmaine
4 months agoViki
5 months agoAaron
5 months agoJamal
7 months agoYoko
7 months agoDerrick
7 months agoJani
8 months agoRonna
7 months agoRima
7 months agoRicarda
8 months agoErasmo
7 months agoLoren
7 months agoMarguerita
7 months agoBernadine
8 months agoVerlene
8 months agoSuzan
8 months agoJunita
9 months agoJanna
8 months agoTijuana
8 months agoMitzie
8 months ago