Describe security capabilities of Microsoft Sentinel Flashcards
Security information and event management (SIEM)
tool that an organization uses to collect data from across the whole estate, including infrastructure, software, and resources
does analysis
looks for correlations / anaomalies
generates alerts and incidents
Security orchestration automated response (SOAR)
takes alerts from many sources - such as SIEM
triggers action driven automated workflows & processes to run security tasks that mitigate the issue
t or f
tool that an organization uses to collect data from across the whole estate, including infrastructure, software, and resources
true
Microsoft Sentinel
scalable cloud native SIEM/SOAR solution that delivers intelligent security analytics and threat intelligence
provides a single solution for alert detection, threat visibility, proactive hunting, and threat response
Microsoft Sentinel
End to end functionality of Microsoft Sentinel
Collect
Detect
Investigare
Respond
Connect Sentinel to your data
Microsoft Defender XDR solutions
Microsoft 365 sources
Microsoft Entra & more
Workbooks
monitor the data using Sentinel integration with Azure Monitor Workbooks
intended for SOC engineers and analysts of all tiers to visualize data
workbooks
type of workbooks
create custom
built in workbook templates
Analytics
correlate alerts into incidents
Incidents
groups of related alerts that together create an actionable possible threat that you can investigate and resolve
Incident management
manage lifecycle of an incident
view all related alerts to said incident
triage and investigate
Security playbooks
a collection of procedures that can help SOC engineers and analysts of all tiers to automate and simplify tasks
How do playbooks work best?
with single, repeatable taks, and require no code knowledge