Sentinel Flashcards
1
Q
Terms
A
Event Management
Automation and Orchestration
Custom Security Alerts
Connectors
- Defender Connector
- Incident
- Rules
- Playbook - Logic Apps
2
Q
Configure the alert to create an incident
A
Defender sends alert to Sentinel
Incident is created
Rule is configured to create a playbook
3
Q
How an incident create a FW rule
A
Incident creates a RULE
RULE creates an Playbook
Playbook invokes LogicApp
LogicApp connects with FW and creates a rule