MicrosoftMicrosoft
SC-200 · Question #396
SC-200 Question #396: Real Exam Question with Answer & Explanation
Sign in or unlock SC-200 to reveal the answer and full explanation for question #396. The question stem and answer options stay visible for context.
Submitted by hans_de· Apr 18, 2026
Question
You have a Microsoft Sentinel workspace. You are investigating an incident that involves the following entities: - A host named Host1 - A user account named User1 - An IP address of 175.45.176.99 You need to update the threat intelligence list to include the entities. Which entities can you add on the Incident page?
Options
- A175.45.176.99 only
- BHost1 only
- CUser1 only
- D175.45.176.99 and Host1 only
- EHost1 and User1 only
- F175.45.176.99, Host1, and User1
Unlock SC-200 to see the answer
You've previewed enough free SC-200 questions. Unlock SC-200 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.