Sentinel Flashcards
(4 cards)
1
Q
SOAR (Security Orchestration Automation and Response)
A
Monitors Incidents
2
Q
SIEM (Security Information and Event Management)
A
Monitors Events
3
Q
KQL Script (Kusto)
A
Monitors events/incidents. (Email forwarding/Intune managed devices/Mass downloads/tenant sharing policy modification/unauthorized PowerShell usage)
4
Q
Actionable Events
A
Email Forwarders/Unauthorized PowerShell usage.