SC-200 • Mock Exam 78
Free SC-200 mock exam — 25 questions with explanations. Set 78. No signup required.
A SOC analyst is investigating a Microsoft Sentinel incident involving a compromised service principal. The analyst needs to enrich the incident with information from an external threat intelligence platform that exposes a REST API and requires an API key. The enrichment must run automatically each time a matching incident is created and must not require manual steps. Which Microsoft Sentinel component should the analyst use to implement this enrichment?
Choose an answer to begin — your selection is scored in the full session.
25 questions · instant feedback and full explanations after every question.