SC-200 Practice Question 3697

Exam: SC-200
Domain: Manage a security operations environment
Difficulty: easy
In Microsoft Sentinel, what is a Watchlist used for in security operations?

Answer Options

A
An imported dataset (CSV) used for correlation in KQL analytics queries
B
A live video stream of the security operations floor
C
A list of corporate employee payroll salaries
D
A physical security badge scanner database

Correct Answer

A: An imported dataset (CSV) used for correlation in KQL analytics queries

Explanation

A Watchlist is an imported dataset (such as a CSV of VIP users, terminated staff, or high-value subnets) that can be joined against incoming event streams in KQL analytics rules.