Microsoft Security Operations Analyst Associate SC-200 Practice Question
You have configured the Microsoft Sentinel TAXII connector to pull domain, IP address, and file hash indicators of compromise (IOCs) from an external threat-intelligence feed. 24 hours later, analysts report that searches against the ThreatIntelligenceIndicator table show the new IOCs, but no alerts or incidents are being raised when log data contains matching entities. To ensure matches against the imported indicators automatically generate security alerts in Microsoft Sentinel, which action should you take next?
Enable and configure the built-in "Threat intelligence (TI) mapping" analytics rule template that maps indicators to log events.
Add the IP addresses to your perimeter firewall's block list to force Sentinel to generate alerts.
Write a new scheduled query rule that joins SecurityEvent with the ThreatIntelligenceIndicator table.
Create a watchlist that contains the imported indicators and reference it from existing analytics rules.
Importing indicators by itself only stores them in the ThreatIntelligenceIndicator table; Microsoft Sentinel will not alert on matches unless an analytics rule evaluates ingested data against those indicators. The built-in "TI map … to indicator" rule templates perform this matching. Enabling and configuring the appropriate TI mapping analytics rule template causes Sentinel to compare every incoming log entry with the indicator set and raise alerts or incidents when a match occurs. Creating a watchlist or a custom scheduled query could work, but the dedicated TI mapping templates are the intended, low-maintenance way to operationalise threat-indicator matching. Blocking the IPs in a firewall has no effect on Sentinel alert generation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the ThreatIntelligenceIndicator table in Microsoft Sentinel?
Open an interactive chat with Bash
What are analytics rule templates in Microsoft Sentinel?
Open an interactive chat with Bash
How does the TAXII connector work in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .