Labeling an IP address entity as an IoC directly from a Sentinel incident
You have a Microsoft Sentinel workspace named SW1. In SW1, you investigate an incident that is associated with the following entities: • Host • IP address • User account • Malware name Which entity can be labeled as an indicator of compromise (IoC) directly from the incident's page?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Sentinel's 'add entity to threat intelligence' supports IP addresses, domains, URLs, and file hashes, so among Host, IP address, User account, and Malware name, only the IP address qualifies for direct IoC labeling.
From a Sentinel incident's page, you can add an entity as a threat indicator (IoC) only for supported types—IP address (IPv4/IPv6), domain, URL, and file hash; of the listed entities, only the IP address can be labeled as an IoC directly.
Assuming a host, user account, or malware name can be added as an IoC — only IP, domain, URL, and file hash entities are supported for direct threat-indicator labeling.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Microsoft Sentinel, you can add only specific entity types as threat indicators directly from an incident: domain name, IP address (IPv4 and IPv6), URL, and file (hash). Of the entities in the incident (Host, IP address, User account, Malware name), the IP address is the only one that matches a supported IoC type.Why the Other Options Are Wrong
Host (B), User account (C), and Malware name (A) are not among the entity types that can be added as threat indicators from the incident page.Community Comment Notes
The community is unanimous (D 100). Studytime2023 cites the add-entity-to-threat-intelligence documentation, and a_kto_to confirms only IP, domain, URL, and file hash can be added as indicators.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →