次のインシデントを含む Microsoft Sentinel ワークスペースがあります。 Azure Portal 分析ルールに対するブルート フォース攻撃がトリガーされました。 インシデントに対応する地理位置情報を特定する必要があります。 あなたは何をするべきか?
正解:B
The IPCustomEntity entity associated with the incident should provide the IP address that triggered the brute force attack. You can then use a geolocation lookup tool to determine the country or region associated with that IP address.