Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities flashcards as text
What type of data connectors does Microsoft Sentinel use to ingest data from Microsoft 365 services?
Answer: Built-in Microsoft connectors
Microsoft Sentinel provides built-in Microsoft connectors that natively integrate with Microsoft 365, Azure AD, and other Microsoft services for seamless data ingestion.
Which Microsoft Sentinel feature allows security analysts to automate responses to detected threats?
Answer: Playbooks
Playbooks in Microsoft Sentinel are automated workflows built on Azure Logic Apps that can execute response actions when an alert or incident is triggered.
What is the primary purpose of Microsoft Sentinel Workbooks?
Answer: To visualize and monitor security data through interactive dashboards
Microsoft Sentinel Workbooks provide interactive visual dashboards built on Azure Monitor Workbooks for monitoring and analyzing security data.
In Microsoft Sentinel, what are Analytics Rules primarily used for?
Answer: Detecting threats by generating alerts from log data
Analytics Rules in Microsoft Sentinel query log data on a schedule and generate security alerts and incidents when suspicious patterns are detected.
Which Microsoft Sentinel component helps analysts proactively search for threats that haven't triggered automated alerts?
Answer: Hunting
Microsoft Sentinel's Hunting capability allows security analysts to proactively query data looking for indicators of compromise before an alert is generated.
What is a Microsoft Sentinel Watchlist?
Answer: A curated set of data imported from external sources used to correlate against event data
Watchlists are imported datasets (such as lists of critical assets or known bad IPs) that can be referenced in analytics rules and hunting queries to enrich detection logic.
Which language is used to write queries in Microsoft Sentinel for log analysis and hunting?
Answer: Kusto Query Language (KQL)
Microsoft Sentinel uses Kusto Query Language (KQL) to query data stored in Log Analytics workspaces for analysis, detection rules, and hunting.