Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE indicators of compromise (IOCs) are commonly used in Microsoft Sentinel to detect advanced persistent threats (APTs)? (Choose THREE.)

⚠ Common exam trap

Watch out — candidates often confuse vulnerability data (Option B) or routine operational events (Option D) with true IOCs, which must directly indicate a past or ongoing compromise rather than a potential risk or normal behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Suspicious domains and URLs.

Option A is correct because suspicious domains and URLs are classic network-based IOCs that Microsoft Sentinel ingests via threat intelligence connectors and matches against DNS, proxy, and firewall logs to surface APT beaconing or phishing infrastructure. Option C is correct because SHA256 file hashes of known malware are high-fidelity, atomic IOCs that Sentinel uses in scheduled analytics rules and the Threat Intelligence matching rule to detect malicious binaries on endpoints and in file events. Option E is correct because IP addresses of known command-and-control servers are standard network IOCs that Sentinel correlates with CommonSecurityLog, Azure Firewall, and DNS data to identify active C2 communication. Option B is not an IOC but a vulnerability assessment artifact describing exposure rather than evidence of compromise, and Option D is a normal operational event (e.g., Event ID 4624) that only becomes suspicious in context, not a standalone IOC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Suspicious domains and URLs.

    Why this is correct

    Suspicious domains and URLs are network-based IOCs that Microsoft Sentinel matches against DNS, proxy, and firewall logs to surface command-and-control beaconing and phishing infrastructure. They satisfy the APT detection requirement because advanced persistent threats routinely rely on domain generation algorithms and compromised legitimate sites, making domain and URL indicators high-fidelity detection signals.

  • ✗

    Vulnerability scan results.

    Why it's wrong here

    Vulnerability scan results are not indicators of compromise because they describe a system's exposure to known weaknesses, such as missing patches or misconfigurations, rather than evidence that an attacker has exploited them. IOCs are forensic artifacts that indicate a network or host has already been breached, such as malware signatures, anomalous network connections, or unauthorized account activity. A vulnerability scan is a proactive security assessment, whereas an IOC is a reactive detection signal, so scan results alone never confirm an intrusion.

  • ✓

    File hashes (SHA256) of known malware.

    Why this is correct

    File hashes such as SHA256 are common file-based indicators of compromise because they uniquely identify a specific malware binary with near-certainty, allowing defenders to detect its presence across endpoints and shared storage. By comparing the hash of a suspicious file to known malware hash feeds, security tools can quickly flag matches even when the file is renamed or disguised. This works because even a single-bit change in the file produces a completely different hash, making exact-match indicators highly reliable for known samples.

  • ✗

    Windows event IDs for successful logins.

    Why it's wrong here

    Windows event IDs for successful logins are not indicators of compromise in isolation because an event ID only describes an action, not the security context around it. A successful logon event (e.g., event ID 4624) is both expected and benign in normal operations, and it becomes suspicious only when paired with additional context such as off-hours activity, impossible travel, unusual source IPs, or abnormal account behavior. Without correlating these contextual clues, event IDs lack the forensic specificity required to count as an IOC.

  • ✓

    IP addresses of known command and control servers.

    Why this is correct

    IP addresses of known command-and-control servers are robust network-based indicators of compromise because they represent the destination of outbound communication from compromised hosts to attacker infrastructure. Threat intelligence platforms curate lists of C2 IPs based on observed malware traffic, and matching a network connection to such an IP strongly suggests an active breach. These indicators are especially useful during incident response to identify infected machines and block further beaconing.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.