[Detection Engineering]
A Custom Prevention rule that was determined to be a false positive alert needs to be tuned. The behavior was determined to be authorized and expected on the affected endpoint. Based on the image below, which two steps could be taken? (Choose two.)
[Image description: A Custom Prevention rule configuration, assumed to trigger a Behavioral Indicator of Compromise (BIOC) alert for authorized behavior]
Jamal
1 days agoJani
7 days agoRicarda
14 days agoBernadine
14 days agoVerlene
16 days agoSuzan
21 days agoJunita
1 months agoJanna
7 days agoTijuana
8 days agoMitzie
1 months ago