SC-200 · Question #396
You have a Microsoft Sentinel workspace. You are investigating an incident that involves the following entities: - A host named Host1 - A user account named User1 - An IP address of 175.45.176.99…
The correct answer is A. 175.45.176.99 only. From the Microsoft Sentinel Incident page, you can directly add IP addresses to your threat intelligence list.
Question
You have a Microsoft Sentinel workspace. You are investigating an incident that involves the following entities:
- A host named Host1
- A user account named User1
- An IP address of 175.45.176.99
You need to update the threat intelligence list to include the entities. Which entities can you add on the Incident page?
Options
- A175.45.176.99 only
- BHost1 only
- CUser1 only
- D175.45.176.99 and Host1 only
- EHost1 and User1 only
- F175.45.176.99, Host1, and User1
How the community answered
(49 responses)- A82% (40)
- C10% (5)
- D4% (2)
- E2% (1)
- F2% (1)
Why each option
From the Microsoft Sentinel Incident page, you can directly add IP addresses to your threat intelligence list.
When investigating incidents in Microsoft Sentinel, you can easily add specific types of entities, such as IP addresses, to your threat intelligence indicators directly from the incident details page. Hostnames and user accounts are not typically added directly as threat indicators from this interface; instead, IP addresses, URLs, and file hashes are common Indicators of Compromise (IOCs) that can be added.
Hostnames are generally not directly added as threat intelligence indicators from the incident page in Sentinel.
User accounts are not directly added as threat intelligence indicators from the incident page in Sentinel.
While IP addresses can be added, hostnames cannot, making this option incorrect.
Neither hostnames nor user accounts are directly added as threat intelligence indicators from the incident page.
This option is incorrect because only IP addresses can be directly added from the incident page among the given choices as threat intelligence indicators.
Concept tested: Microsoft Sentinel threat intelligence integration from incidents
Source: https://learn.microsoft.com/en-us/azure/sentinel/manage-threat-intelligence-from-incidents
Community Discussion
No community discussion yet for this question.