โ† All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities flashcards as text
  1. What is the relationship between Microsoft Sentinel and Azure Log Analytics?

    Answer: Microsoft Sentinel is built on top of Azure Log Analytics workspaces

    Microsoft Sentinel is built on Azure Log Analytics, using the Log Analytics workspace as its underlying data store for all ingested security data.

  2. What does SOAR stand for in the context of Microsoft Sentinel?

    Answer: Security Orchestration, Automation, and Response

    SOAR stands for Security Orchestration, Automation, and Response, and Microsoft Sentinel's playbook functionality provides SOAR capabilities.

  3. Which Microsoft Sentinel feature leverages AI and machine learning to detect anomalies without pre-written rules?

    Answer: Fusion detection

    Microsoft Sentinel's Fusion detection uses machine learning to correlate low-fidelity signals across multiple data sources to detect multi-stage attack scenarios.

  4. What is the purpose of Incidents in Microsoft Sentinel?

    Answer: To group related alerts into a single actionable investigation case

    Incidents in Microsoft Sentinel aggregate related alerts into a single case, providing analysts with a unified view for investigating a potential attack.

  5. Which built-in role grants read-only access to Microsoft Sentinel data, workbooks, and incidents?

    Answer: Microsoft Sentinel Reader

    The Microsoft Sentinel Reader role allows users to view data, incidents, workbooks, and other Sentinel resources without the ability to make changes.

  6. What does Microsoft Sentinel's User and Entity Behavior Analytics (UEBA) feature do?

    Answer: Builds baseline behavioral profiles to detect anomalous user and entity activities

    UEBA in Microsoft Sentinel analyzes user and entity behavior over time to build baselines and then flags deviations that may indicate insider threats or compromised accounts.

  7. How does Microsoft Sentinel reduce alert fatigue for security operations teams?

    Answer: By correlating alerts into incidents and using ML to prioritize high-fidelity detections

    Microsoft Sentinel reduces alert fatigue by using machine learning to correlate related alerts into incidents and suppress low-fidelity noise, helping analysts focus on real threats.