Q: 2
[Detection Engineering]
An analyst considers an alert with the category of lateral movement to be allowed and not needing
to be checked in the future. Based on the image below, which action can an engineer take to address
the requirement?


Options
Discussion
It's B. Honestly, these alert exclusion rule questions are always worded weird but that's the option that handles future alerts cleanly.
Not D, B since it asks about future alerts, but does "best" mean least risky for compliance?
Be respectful. No spam.