nerdexam
Microsoft

SC-100 · Question #67

You have Microsoft Defender for Cloud assigned to Azure management groups. You have a Microsoft Sentinel deployment. During the triage of alerts, you require additional information about the…

The correct answer is B. threat intelligence reports in Defender for Cloud D. Microsoft Sentinel threat intelligence workbooks. The correct answers are B (threat intelligence reports in Defender for Cloud) and D (Microsoft Sentinel threat intelligence workbooks). Threat intelligence reports in Defender for Cloud provide detailed contextual information about detected threats, including actor profiles…

Design security operations, identity, and compliance capabilities

Question

You have Microsoft Defender for Cloud assigned to Azure management groups. You have a Microsoft Sentinel deployment. During the triage of alerts, you require additional information about the security events, including suggestions for remediation. Which two components can you use to achieve the goal? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • Aworkload protections in Defender for Cloud
  • Bthreat intelligence reports in Defender for Cloud
  • CMicrosoft Sentinel notebooks
  • DMicrosoft Sentinel threat intelligence workbooks

How the community answered

(47 responses)
  • A
    11% (5)
  • B
    85% (40)
  • C
    4% (2)

Explanation

The correct answers are B (threat intelligence reports in Defender for Cloud) and D (Microsoft Sentinel threat intelligence workbooks). Threat intelligence reports in Defender for Cloud provide detailed contextual information about detected threats, including actor profiles, attack techniques, and remediation suggestions-making them directly useful during alert triage. Microsoft Sentinel threat intelligence workbooks visualize threat intelligence data and correlate it with security events, also providing remediation context. Workload protections (A) generate alerts but do not themselves surface remediation suggestions. Sentinel notebooks (C) are powerful for deep investigation but require custom coding and are not a ready-made triage aid with built-in remediation guidance.

Topics

#Microsoft Defender for Cloud#Microsoft Sentinel#Threat Intelligence#Security Operations

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice