Describe security capabilities of Microsoft Sentinel Flashcards

(29 cards)

1
Q

Security information and event management (SIEM)

A

tool that an organization uses to collect data from across the whole estate, including infrastructure, software, and resources

does analysis
looks for correlations / anaomalies
generates alerts and incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security orchestration automated response (SOAR)

A

takes alerts from many sources - such as SIEM

triggers action driven automated workflows & processes to run security tasks that mitigate the issue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

t or f

tool that an organization uses to collect data from across the whole estate, including infrastructure, software, and resources

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Microsoft Sentinel

A

scalable cloud native SIEM/SOAR solution that delivers intelligent security analytics and threat intelligence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

provides a single solution for alert detection, threat visibility, proactive hunting, and threat response

A

Microsoft Sentinel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

End to end functionality of Microsoft Sentinel

A

Collect
Detect
Investigare
Respond

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Connect Sentinel to your data

A

Microsoft Defender XDR solutions
Microsoft 365 sources
Microsoft Entra & more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Workbooks

A

monitor the data using Sentinel integration with Azure Monitor Workbooks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

intended for SOC engineers and analysts of all tiers to visualize data

A

workbooks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

type of workbooks

A

create custom
built in workbook templates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Analytics

A

correlate alerts into incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Incidents

A

groups of related alerts that together create an actionable possible threat that you can investigate and resolve

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Incident management

A

manage lifecycle of an incident

view all related alerts to said incident

triage and investigate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Security playbooks

A

a collection of procedures that can help SOC engineers and analysts of all tiers to automate and simplify tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How do playbooks work best?

A

with single, repeatable taks, and require no code knowledge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Investigation

A

tools to help you understand the scope of a potential security threat and find the root cause

17
Q

Hunting

A

search and query tools to proactively hunt for security threats

18
Q

Jupyter Notebooks

A

open source web app that allows you to create and share documents that contain live code, equations, visualizations, and narrative text

19
Q

Community

A

powerful resource for threat detection and automation.

constantly create and add new
-workbooks
-playbooks
-hunting queries
etc

20
Q

Content hub

A

centralized location to discover and manage out of the box packaged solutions

21
Q

top security challenges organizations face

A

increase in number of sophisticated attacks

talent shortage that is driving the need for automation, integration, and consolidation of security tools

visibility into security, privacy, compliance, governance

22
Q

Microsoft Security Copilot

A

AI security product

help defend organizations at mace speed and scale

respond to threats quickly, process signals, assess risk exposure

23
Q

The center of Microsoft Security Copilot is

A

the prompt bar where security analysts can ask q’s in natural language

24
Q

3 primary cases for security posture management

A

Security posture management
Incident response
Security reporting

25
Security posture management
Copilot delivers information on anything that might expose an organization to a known threat gives guidance
26
Incident response
quickly surface an incident
27
security reporting
copilot can deliver customizable reports that are ready to share
28
As the lead admin, it's important to convince your team to start using Microsoft Sentinel. You’ve put together a presentation. What are the four security operation areas of Microsoft Sentinel?
Collect, Detect, Investigate, and Respond
29
Your estate has many different data sources where data is stored. Which tool should be used with Microsoft Sentinel to quickly gain insights across your data as soon as a data source is connected?
Azure Monitor Workbooks