正解:D
In Microsoft Defender for Identity, false positives can occur due to legitimate administrative activities or benign network behavior. To minimize investigation effort, Microsoft recommends reviewing the Resolution Method field associated with the alert's source computer.
The Resolution Method indicates how Defender for Identity classified or resolved the source computer's identity-whether through secure channel (Kerberos/NTLM), DNS resolution, or other identification techniques. If the method is unreliable (e.g., based on DNS name only), it may cause inaccurate correlations that trigger false positives.
By verifying the Resolution Method, analysts can quickly determine whether an alert was raised due to weak identity mapping or misattribution. Microsoft's official documentation states that reviewing the Resolution Method "helps analysts understand how the entity was resolved and assess whether the detection could be a false positive." Hence, to reduce the time spent on false positives, the most relevant data point to review is the Resolution Method of the source computer