Sentinel Flashcards

1
Q

Terms

A

Event Management
Automation and Orchestration
Custom Security Alerts

Connectors
- Defender Connector

  • Incident
  • Rules
  • Playbook - Logic Apps
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Configure the alert to create an incident

A

Defender sends alert to Sentinel
Incident is created
Rule is configured to create a playbook

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How an incident create a FW rule

A

Incident creates a RULE
RULE creates an Playbook
Playbook invokes LogicApp
LogicApp connects with FW and creates a rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly