SC-200 Web TestEngine demo

Exit VCEDump SC-200 Microsoft Security Operations Analyst
Question 52 of 61
0% complete
Q52 Single choice

You have a Microsoft Sentinel workspace named SW1.

In SW1, you investigate an incident that is associated with the following entities:

1. Host
2. IP address
3. User account
4. Malware name

Which entity can be labeled as an indicator of compromise (IoC) directly from the incident's page?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in