SC-200 Practice Question 3793
Exam: SC-200
Domain: Respond to security incidents
Difficulty: hard
You are triaging a high-volume credential harvesting attack in Sentinel. How can an analyst determine whether an IP address in the incident has triggered alerts across other customer tenants globally?
Answer Options
A
Review Microsoft Defender Threat Intelligence integrated on the IP entity page
B
Perform a manual ping test from a local command prompt
C
Call the internet service provider on the telephone
D
Check the local Windows hosts file
Correct Answer
A: Review Microsoft Defender Threat Intelligence integrated on the IP entity page
Explanation
Check Microsoft Threat Intelligence (Defender Threat Intelligence) integrated into the IP entity blade to view global reputation, adversary infrastructure, and passive DNS history.