QuestionQ16
Detection engineeringYour organization uses the curated detection rule set in Google Security Operations (SecOps) for high-priority network indicators. You are seeing a very large number of false positives from your on-premises proxy servers. You need to decrease the number of alerts. What should you do?
- A Configure a rule exclusion for the network.asset.ip field.
- B Configure a rule exclusion for the principal.ip field.
- C Configure a rule exclusion for the target.domain field.
- D Configure a rule exclusion for the target.ip field.
Community Discussion