nerdexam
Microsoft

SC-200 · Question #396

You have a Microsoft Sentinel workspace. You are investigating an incident that involves the following entities: - A host named Host1 - A user account named User1 - An IP address of 175.45.176.99…

The correct answer is A. 175.45.176.99 only. From the Microsoft Sentinel Incident page, you can directly add IP addresses to your threat intelligence list.

Submitted by hans_de· Apr 18, 2026

Question

You have a Microsoft Sentinel workspace. You are investigating an incident that involves the following entities:

  • A host named Host1
  • A user account named User1
  • An IP address of 175.45.176.99

You need to update the threat intelligence list to include the entities. Which entities can you add on the Incident page?

Options

  • A175.45.176.99 only
  • BHost1 only
  • CUser1 only
  • D175.45.176.99 and Host1 only
  • EHost1 and User1 only
  • F175.45.176.99, Host1, and User1

How the community answered

(49 responses)
  • A
    82% (40)
  • C
    10% (5)
  • D
    4% (2)
  • E
    2% (1)
  • F
    2% (1)

Why each option

From the Microsoft Sentinel Incident page, you can directly add IP addresses to your threat intelligence list.

A175.45.176.99 onlyCorrect

When investigating incidents in Microsoft Sentinel, you can easily add specific types of entities, such as IP addresses, to your threat intelligence indicators directly from the incident details page. Hostnames and user accounts are not typically added directly as threat indicators from this interface; instead, IP addresses, URLs, and file hashes are common Indicators of Compromise (IOCs) that can be added.

BHost1 only

Hostnames are generally not directly added as threat intelligence indicators from the incident page in Sentinel.

CUser1 only

User accounts are not directly added as threat intelligence indicators from the incident page in Sentinel.

D175.45.176.99 and Host1 only

While IP addresses can be added, hostnames cannot, making this option incorrect.

EHost1 and User1 only

Neither hostnames nor user accounts are directly added as threat intelligence indicators from the incident page.

F175.45.176.99, Host1, and User1

This option is incorrect because only IP addresses can be directly added from the incident page among the given choices as threat intelligence indicators.

Concept tested: Microsoft Sentinel threat intelligence integration from incidents

Source: https://learn.microsoft.com/en-us/azure/sentinel/manage-threat-intelligence-from-incidents

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice