โ† All SC-900 Flashcard Decks

Microsoft Sentinel as SIEM and SOAR Flashcards

6 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Microsoft Sentinel as SIEM and SOAR flashcards as text
  1. What are the two primary functions that define Microsoft Sentinel's role in a security operations center?

    Answer: SIEM and SOAR

    Microsoft Sentinel combines Security Information and Event Management (SIEM) for collecting and analyzing security data, and Security Orchestration, Automation, and Response (SOAR) for automating responses to threats. This dual capability allows organizations to both detect and react to security incidents from a single platform.

  2. How does Microsoft Sentinel collect log data from various sources like Azure services, Microsoft 365, and on-premises systems?

    Answer: By configuring data connectors

    Data connectors are the built-in components used to ingest data from a wide range of Microsoft and third-party sources into Microsoft Sentinel. They simplify the process of connecting data sources to the Log Analytics workspace that Sentinel uses.

  3. In Microsoft Sentinel, what component, powered by Azure Logic Apps, is used to automate responses to security alerts?

    Answer: Playbooks

    Playbooks in Microsoft Sentinel are collections of procedures that can be run automatically in response to an alert. They are built on Azure Logic Apps, allowing for complex, automated workflows that can interact with various services to contain and remediate threats.

  4. What is the term for a group of related alerts in Microsoft Sentinel that are aggregated to represent a potential security attack?

    Answer: An Incident

    Microsoft Sentinel uses fusion technology and analytics rules to correlate millions of low-fidelity alerts into a manageable number of high-fidelity incidents. An incident is a collection of related alerts that, together, form an actionable attack story.

  5. Which query language is used to create analytics rules, perform threat hunting, and visualize data in Microsoft Sentinel workbooks?

    Answer: Kusto Query Language (KQL)

    Kusto Query Language (KQL) is the language used to query the Log Analytics workspace where all Microsoft Sentinel data is stored. Analysts use KQL to write detection rules, hunt for threats, and build custom visualizations in workbooks.

  6. A security analyst wants to proactively search for new and unknown threats in their organization's data. Which Microsoft Sentinel feature should they use?

    Answer: Hunting

    Threat hunting is the proactive process of searching for cyber threats that are lurking undetected in a network. Microsoft Sentinel provides powerful search and query tools, including built-in hunting queries, to guide security analysts in this process.