Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your security operations center (SOC) needs to ingest indicators of compromise (IOCs) from a partner's TAXII 2.1 server into Microsoft Sentinel. The team wants a built-in solution that can handle authentication and recurring polling of the TAXII collections without requiring any custom scripts or KQL jobs. In addition, the indicators should be written directly into Microsoft Sentinel's native ThreatIntelIndicators table. Which Microsoft Sentinel capability should you configure to meet these requirements?
Create a collection rule that ingests indicators through the Microsoft Graph Security API.
Ingest the feed as a custom log via the Azure Monitor agent.
Enable and configure the Threat intelligence - TAXII data connector.
Build a scheduled analytics rule that uses the externaldata KQL function to query the TAXII feed.
TheThreat intelligence - TAXII data connector is Microsoft Sentinel's built-in TAXII client. After you supply the server URL, collection path, and credentials, the connector polls the TAXII 2.x server on a schedule, retrieves STIX objects, and ingests them into the ThreatIntelIndicators table. Because the connector is native to Sentinel, no extra scripting, API coding, or analytics-rule work is required. In contrast, using the Microsoft Graph Security API, externaldata in an analytics rule, or Azure Monitor custom log ingestion would all require custom development or additional parsing logic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Threat intelligence - TAXII data connector in Microsoft Sentinel?
Open an interactive chat with Bash
What are TAXII and STIX standards in threat intelligence?
Open an interactive chat with Bash
What is the ThreatIntelIndicators table in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .