SC-200 · Question #243
You have a Microsoft Sentinel workspace. You investigate an incident that has the following entities: - A user account named User1 - An IP address of 192.168.10.200 - An Azure virtual machine named…
The correct answer is A. 192.168.10.200. In Microsoft Sentinel, the incidents page allows analysts to label an IP address entity directly as an indicator of compromise (IoC) by adding it to the threat intelligence store. IP addresses are a supported threat intelligence indicator type that can be submitted directly…
Question
You have a Microsoft Sentinel workspace. You investigate an incident that has the following entities:
- A user account named User1
- An IP address of 192.168.10.200
- An Azure virtual machine named VM1
- An on-premises server named Server1
You need to label an entity as an indicator of compromise (IoC) directly by using the incidents page. Which entity can you label?
Options
- A192.168.10.200
- BVM1
- CServer1
- DUser1
How the community answered
(28 responses)- A89% (25)
- B4% (1)
- D7% (2)
Explanation
In Microsoft Sentinel, the incidents page allows analysts to label an IP address entity directly as an indicator of compromise (IoC) by adding it to the threat intelligence store. IP addresses are a supported threat intelligence indicator type that can be submitted directly from the entity panel within an incident. User accounts (D), Azure virtual machines (B), and on-premises servers (C) are entity types that Sentinel tracks and links to incidents, but they cannot be directly labeled as IoC indicators from the incidents page - those entity types are not natively submittable as threat intelligence indicators through that UI path.
Topics
Community Discussion
No community discussion yet for this question.