Describe security capabilities of Microsoft Sentinel Flashcards

1
Q

Security information and event management (SIEM)

A

tool that an organization uses to collect data from across the whole estate, including infrastructure, software, and resources

does analysis
looks for correlations / anaomalies
generates alerts and incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security orchestration automated response (SOAR)

A

takes alerts from many sources - such as SIEM

triggers action driven automated workflows & processes to run security tasks that mitigate the issue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

t or f

tool that an organization uses to collect data from across the whole estate, including infrastructure, software, and resources

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Microsoft Sentinel

A

scalable cloud native SIEM/SOAR solution that delivers intelligent security analytics and threat intelligence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

provides a single solution for alert detection, threat visibility, proactive hunting, and threat response

A

Microsoft Sentinel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

End to end functionality of Microsoft Sentinel

A

Collect
Detect
Investigare
Respond

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Connect Sentinel to your data

A

Microsoft Defender XDR solutions
Microsoft 365 sources
Microsoft Entra & more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Workbooks

A

monitor the data using Sentinel integration with Azure Monitor Workbooks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

intended for SOC engineers and analysts of all tiers to visualize data

A

workbooks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

type of workbooks

A

create custom
built in workbook templates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Analytics

A

correlate alerts into incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Incidents

A

groups of related alerts that together create an actionable possible threat that you can investigate and resolve

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Incident management

A

manage lifecycle of an incident

view all related alerts to said incident

triage and investigate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Security playbooks

A

a collection of procedures that can help SOC engineers and analysts of all tiers to automate and simplify tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How do playbooks work best?

A

with single, repeatable taks, and require no code knowledge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Investigation

A

tools to help you understand the scope of a potential security threat and find the root cause

17
Q

Hunting

A

search and query tools to proactively hunt for security threats

18
Q

Jupyter Notebooks

A

open source web app that allows you to create and share documents that contain live code, equations, visualizations, and narrative text

19
Q

Community

A

powerful resource for threat detection and automation.

constantly create and add new
-workbooks
-playbooks
-hunting queries
etc

20
Q

Content hub

A

centralized location to discover and manage out of the box packaged solutions

21
Q

top security challenges organizations face

A

increase in number of sophisticated attacks

talent shortage that is driving the need for automation, integration, and consolidation of security tools

visibility into security, privacy, compliance, governance

22
Q

Microsoft Security Copilot

A

AI security product

help defend organizations at mace speed and scale

respond to threats quickly, process signals, assess risk exposure

23
Q

The center of Microsoft Security Copilot is

A

the prompt bar where security analysts can ask q’s in natural language

24
Q

3 primary cases for security posture management

A

Security posture management
Incident response
Security reporting

25
Q

Security posture management

A

Copilot delivers information on anything that might expose an organization to a known threat

gives guidance

26
Q

Incident response

A

quickly surface an incident

27
Q

security reporting

A

copilot can deliver customizable reports that are ready to share

28
Q

As the lead admin, it’s important to convince your team to start using Microsoft Sentinel. You’ve put together a presentation. What are the four security operation areas of Microsoft Sentinel?

A

Collect, Detect, Investigate, and Respond

29
Q

Your estate has many different data sources where data is stored. Which tool should be used with Microsoft Sentinel to quickly gain insights across your data as soon as a data source is connected?

A

Azure Monitor Workbooks