Q52
Single choice
You have a Microsoft Sentinel workspace named SW1.
In SW1, you investigate an incident that is associated with the following entities:
1. Host
2. IP address
3. User account
4. Malware name
Which entity can be labeled as an indicator of compromise (IoC) directly from the incident's page?