SC-200 Practice Question 3837

Exam: SC-200
Domain: Perform threat hunting
Difficulty: easy
You are threat hunting in Microsoft Sentinel and discover an ongoing advanced persistent threat. You want to package all your bookmarked findings, linked entities, and query outputs into a formal case. What action should you take?

Answer Options

A
Select bookmarks in the Hunting blade and click "Add to incident"
B
Delete the bookmarks and start a new hunt
C
Copy query text into a local text file
D
Print the query outputs onto paper

Correct Answer

A: Select bookmarks in the Hunting blade and click "Add to incident"

Explanation

Select the bookmarks in the Hunting blade and click "Add to incident" (or "Create new incident") to transition the threat hunt into an active incident response investigation.