ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 248 - SC-200 discussion

Report
Export

You have a Microsoft Sentinel workspace named SW1.

In SW1, you investigate an incident that is associated with the following entities:

* Host

* IP address

* User account

* Malware name

Which entity can be labeled as an indicator of compromise (loC) directly from the incident s page?

A.

malware name

Answers
A.

malware name

B.

host

Answers
B.

host

C.

user account

Answers
C.

user account

D.

IP address

Answers
D.

IP address

Suggested answer: D
asked 05/10/2024
ben ebrahimi
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first