Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities flashcards as text
Which pricing model does Microsoft Sentinel use for data ingestion?
Answer: Pay-as-you-go based on GB of data ingested, or commitment tiers
Microsoft Sentinel uses a consumption-based pricing model where organizations pay per GB of data ingested, with commitment tiers available for predictable workloads.
What is the Microsoft Sentinel Content Hub?
Answer: A central location to discover and deploy packaged solutions including connectors, rules, and workbooks
The Microsoft Sentinel Content Hub is a centralized marketplace where organizations can find and deploy out-of-the-box solutions that include data connectors, analytics rules, and workbooks for specific products.
Which Microsoft Sentinel capability allows analysts to collaborate on investigations and document findings in a shared space?
Answer: Notebooks
Microsoft Sentinel Notebooks, powered by Jupyter Notebooks, allow analysts to document investigations, run advanced queries, and collaborate using a shareable interactive environment.
What type of threat intelligence can be imported into Microsoft Sentinel to enhance detections?
Answer: Indicators of Compromise (IOCs) such as malicious IPs, URLs, and file hashes from TAXII or STIX feeds
Microsoft Sentinel can ingest threat intelligence data in STIX/TAXII format, including IOCs like malicious IPs, domains, and file hashes, which are used to enrich analytics rules.
What is the role of the Microsoft Sentinel Contributor RBAC role?
Answer: Create and edit workbooks, analytics rules, playbooks, and manage incidents
The Microsoft Sentinel Contributor role allows users to create and edit workbooks, analytics rules, playbooks, and other Sentinel resources, as well as manage incidents.
Which feature in Microsoft Sentinel maps detected threats to the MITRE ATT&CK framework?
Answer: MITRE ATT&CK coverage view in Analytics and Threat Intelligence
Microsoft Sentinel includes a MITRE ATT&CK framework view in the Analytics section that maps your enabled detection rules to specific tactics and techniques to show coverage.
In Microsoft Sentinel, what is the difference between an alert and an incident?
Answer: An alert is a single detection event; an incident groups one or more related alerts for investigation
An alert is an individual detection from an analytics rule, while an incident is a grouped collection of related alerts that together form an investigation case for analysts.