4: Incidents Flashcards

(13 cards)

1
Q

What is an incident in Microsoft Sentinel?

A

A group of related alerts bundled together to tell a broader attack story.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Where do you view incidents?

A

Microsoft Sentinel > [Workspace] > Incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What information does an incident contain?

A

Associated alerts, entities, severity, investigation timeline, graph view, status, assignment, and comments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of grouping alerts into incidents?

A

It reduces alert fatigue by showing a coherent view of related activity instead of flooding analysts with noise.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the investigation graph?

A

A visual map of alerts and entities in an incident that helps analysts understand the scope and progression of the attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can I manually create or assign incidents?

A

Yes. You can manually create, assign, tag, and manage incidents in Sentinel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What can you do from the incident pane?

A

Review alerts, view timelines, launch automation, comment, assign, and change incident status.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why should customers care about incidents?

A

Incidents give analysts a streamlined, contextual view of what’s happening, enabling faster triage and investigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What’s the difference between an alert and an incident?

A

An alert is one signal firing; an incident groups multiple related alerts into a single investigation case.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Can automation be triggered from incidents?

A

Yes. Playbooks can be launched manually or automatically from incident triggers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What entities are typically shown in an incident?

A

Users, hosts, IP addresses, mailboxes, apps—any object tied to the alerts in the incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the benefits of the timeline view in incidents?

A

It shows the chronological order of alerts and helps analysts reconstruct the sequence of attacker behavior.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What’s the benefit of assigning incidents to users?

A

It supports workflow and accountability in the SOC—ensures every incident is being tracked and resolved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly