nerdexam
Microsoft

SC-200 · Question #30

You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC). What should you use?

The correct answer is A. notebooks in Azure Sentinel. Notebooks in Azure Sentinel are the correct tool for this requirement. Azure Sentinel integrates with Jupyter Notebooks, which support rich custom visualizations and can connect to third-party data sources, threat intelligence feeds, and APIs to enrich investigation data…

Submitted by ngozi_ng· Apr 18, 2026Manage threat hunting in Microsoft Sentinel

Question

You need to visualize Azure Sentinel data and enrich the data by using third-party data sources to identify indicators of compromise (IoC). What should you use?

Options

  • Anotebooks in Azure Sentinel
  • BMicrosoft Cloud App Security
  • CAzure Monitor
  • Dhunting queries in Azure Sentinel

How the community answered

(47 responses)
  • A
    83% (39)
  • B
    11% (5)
  • C
    2% (1)
  • D
    4% (2)

Explanation

Notebooks in Azure Sentinel are the correct tool for this requirement. Azure Sentinel integrates with Jupyter Notebooks, which support rich custom visualizations and can connect to third-party data sources, threat intelligence feeds, and APIs to enrich investigation data. Notebooks also support Python-based machine learning libraries (such as scikit-learn) that can be used to identify indicators of compromise. Microsoft Cloud App Security is a separate CASB product. Azure Monitor is a general observability platform. Hunting queries in Sentinel use KQL and are useful for searching, but lack the deep visualization and third-party data enrichment capabilities of notebooks.

Topics

#Azure Sentinel#Notebooks#Data Enrichment#Threat Hunting

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice