nerdexam
Microsoft

SC-200 · Question #328

You have a Microsoft Sentinel workspace named SW1. In SW1, you investigate an incident that is associated with the following entities: - Host - IP address - User account - Malware name Which entity…

The correct answer is D. IP address. From a Microsoft Sentinel incident, an IP address entity can be directly labeled as an Indicator of Compromise (IoC) because it represents a specific observable that can be used for threat detection and prevention.

Submitted by salim_om· Apr 18, 2026

Question

You have a Microsoft Sentinel workspace named SW1. In SW1, you investigate an incident that is associated with the following entities:

  • Host
  • IP address
  • User account
  • Malware name

Which entity can be labeled as an indicator of compromise (IoC) directly from the incident's page?

Options

  • Amalware name
  • Bhost
  • Cuser account
  • DIP address

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    4% (1)
  • D
    81% (22)

Why each option

From a Microsoft Sentinel incident, an IP address entity can be directly labeled as an Indicator of Compromise (IoC) because it represents a specific observable that can be used for threat detection and prevention.

Amalware name
Bhost
Cuser account

A 'user account' is an affected *identity*. While a compromised user account is central to an incident, the user account *name* itself is not a specific observable that functions as an IoC in the context of threat intelligence feeds; rather, suspicious login IPs or activity patterns associated with the user might be.

DIP addressCorrect

An IP address, especially if it's associated with malicious activity (e.g., a command-and-control server or a source of an attack), is a classic Indicator of Compromise (IoC). Microsoft Sentinel allows security analysts to easily create threat intelligence indicators directly from IP address entities found within an incident for use in detection rules and threat intelligence lookups.

Concept tested: Microsoft Sentinel Incident entities and IoC creation

Source: https://learn.microsoft.com/en-us/azure/sentinel/create-custom-indicators-from-incidents

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice