Which statement correctly explains what disabling the IOC will accomplish?

An analyst on the security team noticed that several alerts are false positives within Enterprise EDR. The analyst disables the IOC within the report from those alerts.
Which statement correctly explains what disabling the IOC will accomplish?
A. That specific IOC in the report will no longer generate hits or alerts on the device from the alert.
B. The report will no longer generate hits or alerts on the device from the alert.
C. That specific IOC in the report will no longer generate hits or alerts.
D. The report will no longer generate hits or alerts.

microsoft-exams

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.