SC-200 Perform threat hunting • 50 Questions
50 SC-200 Perform threat hunting practice questions with answers and explanations. Free, no signup.
During a threat hunt in Microsoft Sentinel, an analyst creates a custom hunting query that uses the 'externaldata' operator to reference a CSV file stored in Azure Blob Storage. The hunt identifies several suspicious IP addresses that need to be added to a threat intelligence indicator. Which method should the analyst use to persist the findings as indicators of compromise (IOCs) for automated alerting?
Choose an answer to begin — your selection is scored in the full session.
50 questions · instant feedback and full explanations after every question.