← All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities flashcards as text
  1. Which Microsoft Sentinel analytics rule type runs on a fixed schedule and queries historical log data?

    Answer: Scheduled analytics rules

    Scheduled analytics rules in Microsoft Sentinel run KQL queries against log data at configurable intervals (e.g., every 5 minutes or every hour) to detect threats in historical data.

  2. What is the purpose of Near-Real-Time (NRT) analytics rules in Microsoft Sentinel?

    Answer: To provide alert generation within about one minute of data ingestion for time-sensitive detections

    NRT rules in Microsoft Sentinel run approximately every minute, providing much faster detection than standard scheduled rules for high-priority, time-sensitive threat scenarios.

  3. Which Microsoft Sentinel feature allows security teams to simulate attacks and test their detection coverage?

    Answer: Hunting queries with simulation tags

    Security teams can create hunting queries tagged for specific attack simulations to test whether their analytics rules and detections would catch particular adversarial behaviors.

  4. What does the Microsoft Sentinel Responder role allow users to do?

    Answer: Manage and act on incidents (assign, change status, add comments) but not create or modify analytics rules

    The Microsoft Sentinel Responder role allows analysts to manage incidents — assign them, update their status, and add comments — but not modify the underlying detection configurations.

  5. How does Microsoft Sentinel handle multi-cloud environments?

    Answer: It can ingest data from AWS, GCP, and other cloud providers through data connectors

    Microsoft Sentinel supports multi-cloud environments by providing data connectors for AWS services (like CloudTrail and S3), GCP, and other third-party cloud platforms.

  6. What is the primary benefit of using Microsoft Sentinel as a cloud-native SIEM over traditional on-premises SIEM solutions?

    Answer: It eliminates infrastructure management and scales automatically with data volume

    As a cloud-native SIEM, Microsoft Sentinel removes the burden of managing servers and storage hardware, and scales elastically to accommodate growing data volumes without capacity planning.

  7. Which Microsoft Sentinel feature provides a visual representation of an attack's progression across entities like users, hosts, and IPs during an investigation?

    Answer: The Investigation Graph

    The Investigation Graph in Microsoft Sentinel visually maps relationships between entities (users, devices, IPs) involved in an incident to help analysts understand the scope and progression of an attack.