nerdexam
Microsoft

MS-102 · Question #583

You have a Microsoft 365 subscription. You create a Microsoft Defender Threat Intelligence (Defender TI) project named Project1. You need to add artifacts to Project1. Which type of artifact can you…

The correct answer is C. IP addresses. In a Microsoft Defender Threat Intelligence (Defender TI) project, users can add key infrastructure artifacts-specifically IPs, domains, and hostnames-to organize, analyze, and enrich investigation data. Projects allow for tracking, tagging, and visualizing relationships…

Submitted by kevin_r· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 subscription. You create a Microsoft Defender Threat Intelligence (Defender TI) project named Project1. You need to add artifacts to Project1. Which type of artifact can you add to Project1?

Options

  • AMicrosoft SharePoint Online sites
  • Bnetwork segments
  • CIP addresses
  • DMicrosoft Entra users

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    96% (25)

Explanation

In a Microsoft Defender Threat Intelligence (Defender TI) project, users can add key infrastructure artifacts-specifically IPs, domains, and hostnames-to organize, analyze, and enrich investigation data. Projects allow for tracking, tagging, and visualizing relationships between these indicators of compromise (IOCs). Key Artifact Types to Add: *-> IP Addresses: Both IPv4 and IPv6 addresses. Domains: Including subdomains. Hostnames: Specific server names. File Hashes: Associated with malware or tools (SHA-1, SHA-256). https://learn.microsoft.com/en-us/defender/threat-intelligence/using-projects

Topics

#Defender Threat Intelligence#TI artifacts#IP addresses

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice