Labeling an IP address entity as an IoC directly from a Sentinel incident

Ingest data into the Microsoft Sentinel SIEM and platform
Answer Correct answer: D — Only IP address (along with domain, URL, file hash) is a supported entity type you can label as an IoC from the incident page.

You have a Microsoft Sentinel workspace named SW1. In SW1, you investigate an incident that is associated with the following entities: • Host • IP address • User account • Malware name Which entity can be labeled as an indicator of compromise (IoC) directly from the incident's page?

  1. malware name
  2. host
  3. user account
  4. IP address Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Sentinel's 'add entity to threat intelligence' supports IP addresses, domains, URLs, and file hashes, so among Host, IP address, User account, and Malware name, only the IP address qualifies for direct IoC labeling.

From a Sentinel incident's page, you can add an entity as a threat indicator (IoC) only for supported types—IP address (IPv4/IPv6), domain, URL, and file hash; of the listed entities, only the IP address can be labeled as an IoC directly.

Assuming a host, user account, or malware name can be added as an IoC — only IP, domain, URL, and file hash entities are supported for direct threat-indicator labeling.

Community Discussion (5 comments)

a_kto_to 👍 1 Selected: D
"Add only the following types of entities as threat indicators: Domain name IP address (IPv4 and IPv6) URL File (hash) "
sapphire 👍 1 Selected: D
Correct answer is IP
f6ba8a1 👍 1
I think Hash can be labeled as IoC
Studytime2023 👍 2 Selected: D
Correct https://learn.microsoft.com/en-us/azure/sentinel/add-entity-to-threat-intelligence?tabs=incidents#add-an-entity-to-your-threat-intelligence
90158a0 👍 1 Selected: D
IP Address

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Microsoft Sentinel, you can add only specific entity types as threat indicators directly from an incident: domain name, IP address (IPv4 and IPv6), URL, and file (hash). Of the entities in the incident (Host, IP address, User account, Malware name), the IP address is the only one that matches a supported IoC type.

Why the Other Options Are Wrong

Host (B), User account (C), and Malware name (A) are not among the entity types that can be added as threat indicators from the incident page.

Community Comment Notes

The community is unanimous (D 100). Studytime2023 cites the add-entity-to-threat-intelligence documentation, and a_kto_to confirms only IP, domain, URL, and file hash can be added as indicators.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide