nerdexam
Microsoft

SC-200 · Question #243

You have a Microsoft Sentinel workspace. You investigate an incident that has the following entities: - A user account named User1 - An IP address of 192.168.10.200 - An Azure virtual machine named…

The correct answer is A. 192.168.10.200. In Microsoft Sentinel, the incidents page allows analysts to label an IP address entity directly as an indicator of compromise (IoC) by adding it to the threat intelligence store. IP addresses are a supported threat intelligence indicator type that can be submitted directly…

Submitted by rohit_dlh· Apr 18, 2026Manage incident response

Question

You have a Microsoft Sentinel workspace. You investigate an incident that has the following entities:

  • A user account named User1
  • An IP address of 192.168.10.200
  • An Azure virtual machine named VM1
  • An on-premises server named Server1

You need to label an entity as an indicator of compromise (IoC) directly by using the incidents page. Which entity can you label?

Options

  • A192.168.10.200
  • BVM1
  • CServer1
  • DUser1

How the community answered

(28 responses)
  • A
    89% (25)
  • B
    4% (1)
  • D
    7% (2)

Explanation

In Microsoft Sentinel, the incidents page allows analysts to label an IP address entity directly as an indicator of compromise (IoC) by adding it to the threat intelligence store. IP addresses are a supported threat intelligence indicator type that can be submitted directly from the entity panel within an incident. User accounts (D), Azure virtual machines (B), and on-premises servers (C) are entity types that Sentinel tracks and links to incidents, but they cannot be directly labeled as IoC indicators from the incidents page - those entity types are not natively submittable as threat intelligence indicators through that UI path.

Topics

#Incident response#Indicators of Compromise (IoC)#Microsoft Sentinel#Entity management

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice