5: Workbooks Flashcards

(14 cards)

1
Q

What is a workbook in Microsoft Sentinel?

A

An interactive, customizable dashboard that visualizes data from your logs using charts, tables, KPIs, and other visuals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Where do you access workbooks in Sentinel?

A

Microsoft Sentinel > [Workspace] > Workbooks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are workbooks used for?

A

Monitoring, investigation, reporting, and high-level visibility across your environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What kinds of visuals can workbooks display?

A

Line graphs, pie charts, tables, KPIs, heatmaps, bar graphs, and more.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can you create your own workbooks?

A

Yes, using KQL queries and drag-and-drop configuration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can workbooks be customized?

A

Yes. You can edit, filter, clone, or modify them to match your mission set, enclave, or role.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What kind of data can be shown in a workbook?

A

Any data stored in Log Analytics—alerts, sign-ins, audit logs, network activity, threat intel, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What’s the difference between a workbook and a dashboard?

A

Workbooks are dynamic and built from KQL queries; dashboards are more static and pin individual tiles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why are workbooks useful to customers?

A

They give real-time insight into trends, anomalies, and health across tools and enclaves, and support both analyst workflows and executive reporting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Can I use workbooks for executive summaries?

A

Yes. You can build high-level overviews with KPIs, alert trends, and visuals tailored for leadership.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Do data connectors come with prebuilt workbooks?

A

Often yes—especially for Defender, Azure AD, Office 365, and common log sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What’s a use case for workbook heatmaps?

A

Visualizing login attempts by country or IP to identify geographic anomalies or access attempts from unfamiliar locations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What’s the advantage of trend-over-time visuals in a workbook?

A

They help spot unusual spikes, drops, or emerging patterns in activity or alert volume.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Can you filter workbook data by host, user, time, or product?

A

Yes. Workbooks are highly filterable to support focused investigation or enclave-specific views.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly