The basics Flashcards

1
Q

What is Azure Sentinel?

A

A cloud-native SIEM (Security Information and Event Management) platform provided by Microsoft.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does Azure Sentinel work?

A

It uses AI to analyse data from your entire environment, helping you detect and respond to threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What can I use Azure Sentinel for?

A
  • Centralized security monitoring: Collect data from all sources (on-premises, cloud, devices) and get a unified view of your security posture.
  • Threat detection and investigation: Leverage built-in AI and threat intelligence to identify suspicious activity and quickly investigate potential threats.
  • Proactive threat hunting: Uncover hidden threats and vulnerabilities before they cause damage.
  • Automated response and remediation: Orchestrate actions to contain threats and minimize impact.
  • Compliance reporting and auditing: Meet security regulations and track your security posture over time.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How do threats look in Azure Sentinel?

A
  • Suspicious events: Unusual login attempts, high data transfers, malware detections, etc.
  • Anomalies: Deviations from normal user or device behaviour, identified by AI.
  • Correlated events: Seemingly unrelated events that, when combined, point to a potential threat.
  • Indicators of compromise (IOCs): Known malicious signatures or patterns associated with specific threats.
  • Threat intelligence feeds: Updated information about the latest threats and vulnerabilities.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some key features of Azure Sentinel?

A
  • Cloud-native: Scalable and elastic, no need for on-premises infrastructure.
  • Built-in AI: Reduces false positives and improves threat detection accuracy.
  • Rich threat intelligence: Access to Microsoft’s vast security expertise and real-time threat data.
  • Open and extensible: Integrates with other security tools and services.
  • Cost-effective: Pay-as-you-go pricing based on data ingestion and storage.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the four pillars of Azure Sentinel?

A

Collect, detect, investigate, and respond

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the query language used by Azure Sentinel?

A

Kusto Query Language (KQL)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you onboard Azure Sentinel to a Log Analytics workspace?

A

Search for Microsoft Sentinel and click “create”, then add Sentinel to the workspace or create a new one

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How do you deploy data connectors to start logging data from various sources?

A

On Sentinel’s GUI, select Data connectors, then click the connector you want to use and follow the instructions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How does Azure Sentinel use AI to investigate threats and reduce false positives?

A

Azure Sentinel uses machine learning and knowledge based on analysing “trillions” of signals daily to correlate and prioritize alerts, and to provide guided investigation and hunting queries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How do you respond to incidents rapidly with Azure Sentinel?

A

You can use built-in orchestration and automation of common tasks by using playbooks, which are based on Azure Logic Apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are some of the data sources that Azure Sentinel can collect data from?

A

Azure, on-premises, and other cloud platforms, with built-in or custom connectors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How does Azure Sentinel detect threats and minimize false positives?

A

It uses advanced analytics, machine learning, and threat intelligence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How does Azure Sentinel investigate and hunt for suspicious activities?

A

It uses AI and interactive dashboards to investigate and hunt at scale.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does Azure Sentinel respond to incidents quickly and efficiently?

A

It uses built-in or custom playbooks to automate and orchestrate tasks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the benefits of using a cloud-native SIEM solution like Azure Sentinel?

A

A cloud-native SIEM solution like Azure Sentinel eliminates the need for infrastructure setup and maintenance, scales to meet the security needs, and reduces costs compared to legacy SIEMs.

17
Q

What are some of the Azure services that Microsoft Sentinel natively incorporates?

A

Microsoft Sentinel natively incorporates Azure services like Log Analytics and Logic Apps.

18
Q

How does Microsoft Sentinel enrich the investigation and detection with AI?

A

Microsoft Sentinel provides Microsoft’s threat intelligence stream and enables you to bring your own threat intelligence. It also uses machine learning to reduce noise and false positives.

19
Q

What is Azure Sentinel?

A

A cloud-native product that handles security data and threats.

20
Q

How does Azure Sentinel integrate data sources?

A

It connects with Microsoft and third-party solutions, supports common formats and API, and lets users add their own intelligence and data.

21
Q

How does Azure Sentinel detect threats?

A

It uses templates and rules, creates incidents from alerts, shows a visual graph of the kill chain, and lets users hunt and analyse threats.

22
Q

How does Azure Sentinel respond to threats?

A

It uses playbooks based on Logic Apps to automate or trigger responses, works with Microsoft and third-party tools, and gives examples of playbooks.

23
Q

How does Azure Sentinel use advanced capabilities?

A

It uses behavioural analytics to find anomalies and impact, uses notebooks to apply machine learning and analytics, and uses watch lists to create lists based on external data.

24
Q

How does Azure Sentinel use metrics and reporting?

A

It uses workbook to show metrics, uses Power BI to create dashboards and reports, and shares insights and practices with GitHub.

25
Q

What are the two main capabilities of Microsoft Sentinel?

A

Security information and event management (SIEM) and security orchestration, automation, and response (SOAR).

26
Q

What are some of the sources of security data that Microsoft Sentinel can collect and analyse?

A

Azure, on-premises, and other clouds.

27
Q

What are some of the tools that Microsoft Sentinel uses to detect and investigate threats?

A

Built-in analytics, artificial intelligence, and threat intelligence from Microsoft.

28
Q

What are some of the common security tasks that Microsoft Sentinel can automate and orchestrate using playbooks and logic apps?

A

Alert triage, incident response, threat hunting, etc.

29
Q

What are some of the threats that Microsoft Sentinel can help you identify and mitigate?

A

Advanced persistent threats (APTs), ransomware attacks, phishing campaigns, etc.

30
Q

How are threats represented in Microsoft Sentinel?

A

Alerts and incidents. Alerts are notifications of suspicious or malicious activities that require further investigation. Incidents are collections of related alerts that indicate a potential breach or compromise.

31
Q

How can you view and manage alerts and incidents in Microsoft Sentinel?

A

In the Microsoft Sentinel portal, where you can also access interactive reports, dashboards, and hunting tools.