Monitoring M365 Security with Azure Sentinel Flashcards
Microsoft Azure Sentinel uses analytics to correlate _____ into incidents.
A. data points
B. alerts
C. responses
D. events
E. I don’t know
B. alerts
Explanation:
Azure Sentinel uses analytics to correlate alerts into incidents.
What is Microsoft Azure Sentinel?
A. a VPN gateway for establishing secure, cross-premises connectivity
B. a cloud-native web application firewall service that provides powerful protection for web apps
C. a cloud-native security information and event management system and a security orchestration automated response solution
D. a unified solution for remotely verifying the trustworthiness of a platform and integrity of the binaries running inside it
E. I don’t know
C. a cloud-native security information and event management system and a security orchestration automated response solution
Explanation:
Microsoft Azure Sentinel is a cloud-native security information and event management system, or SIEM. It’s also a security orchestration automated response solution, or SOAR.
Microsoft Azure Sentinel offers automation and orchestration features that allow you to automate common tasks and to simplify security orchestration with _____, which you can build with Azure Logic Apps.
A. scripts
B. cookbooks
C. playbooks
D. logic recipes
E. I don’t know
C. playbooks
Explanation:
Azure Sentinel is built on the foundation of Azure Logic Apps. Because of this, Azure Sentinel offers automation and orchestration features that allow you to automate common tasks and to simplify security orchestration with playbooks, which you can build with Azure Logic Apps
Which Microsoft Azure Sentinel data connector allows you to analyze security events across the organization and build playbooks to facilitate a more effective and immediate response to threats?
A. Microsoft Defender for Endpoint connector
B. Microsoft Azure Security Center connector
C. Microsoft Office 365 Log connector
D. Microsoft Azure Active Directory connector
E. I don’t know
A. Microsoft Defender for Endpoint connector
Explanation:
Azure Sentinel’s Microsoft Defender for Endpoint connector can be used to stream alerts from Microsoft Defender for Endpoint into Azure Sentinel. This allows you to analyze security events across the organization, and it also allows you to build playbooks to facilitate a more effective and immediate response to threats.
Microsoft Azure Sentinel is built on the foundation of Azure _____.
A. Logic Apps
B. Application Gateway
C. Cosmos DB
D. Monitor Workbooks
E. I don’t know
A. Logic Apps
Explanation:
Azure Sentinel is built on the foundation of Azure Logic Apps.