Sentinel Flashcards

(4 cards)

1
Q

SOAR (Security Orchestration Automation and Response)

A

Monitors Incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

SIEM (Security Information and Event Management)

A

Monitors Events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

KQL Script (Kusto)

A

Monitors events/incidents. (Email forwarding/Intune managed devices/Mass downloads/tenant sharing policy modification/unauthorized PowerShell usage)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Actionable Events

A

Email Forwarders/Unauthorized PowerShell usage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly