nerdexam
Microsoft

SC-200 · Question #232

You need to visualize Microsoft Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC). What should you use?

The correct answer is A. notebooks in Microsoft Sentinel. Notebooks are interactive tools that allow you to run Python code, query data, perform machine learning, and create visualizations. Notebooks can help you hunt for threats, investigate incidents, and perform data analysis using Microsoft Sentinel data and external data sources.

Submitted by emma.c· Apr 18, 2026Manage threat hunting in Microsoft Sentinel

Question

You need to visualize Microsoft Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC). What should you use?

Options

  • Anotebooks in Microsoft Sentinel
  • BMicrosoft Defender for Cloud Apps
  • CAzure Monitor

How the community answered

(24 responses)
  • A
    75% (18)
  • B
    17% (4)
  • C
    8% (2)

Explanation

Notebooks are interactive tools that allow you to run Python code, query data, perform machine learning, and create visualizations. Notebooks can help you hunt for threats, investigate incidents, and perform data analysis using Microsoft Sentinel data and external data sources.

Topics

#Microsoft Sentinel#Notebooks#Data enrichment#IoC identification

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice