List of questions
Related questions
Question 248 - SC-200 discussion
You have a Microsoft Sentinel workspace named SW1.
In SW1, you investigate an incident that is associated with the following entities:
* Host
* IP address
* User account
* Malware name
Which entity can be labeled as an indicator of compromise (loC) directly from the incident s page?
A.
malware name
B.
host
C.
user account
D.
IP address
Your answer:
0 comments
Sorted by
Leave a comment first