SC-200 · Question #30
You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC). What should you use?
The correct answer is A. notebooks in Azure Sentinel. Notebooks in Azure Sentinel are the correct tool for this requirement. Azure Sentinel integrates with Jupyter Notebooks, which support rich custom visualizations and can connect to third-party data sources, threat intelligence feeds, and APIs to enrich investigation data…
Question
You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC). What should you use?
Options
- Anotebooks in Azure Sentinel
- BMicrosoft Cloud App Security
- CAzure Monitor
- Dhunting queries in Azure Sentinel
How the community answered
(47 responses)- A83% (39)
- B11% (5)
- C2% (1)
- D4% (2)
Explanation
Notebooks in Azure Sentinel are the correct tool for this requirement. Azure Sentinel integrates with Jupyter Notebooks, which support rich custom visualizations and can connect to third-party data sources, threat intelligence feeds, and APIs to enrich investigation data. Notebooks also support Python-based machine learning libraries (such as scikit-learn) that can be used to identify indicators of compromise. Microsoft Cloud App Security is a separate CASB product. Azure Monitor is a general observability platform. Hunting queries in Sentinel use KQL and are useful for searching, but lack the deep visualization and third-party data enrichment capabilities of notebooks.
Topics
Community Discussion
No community discussion yet for this question.