SC-900 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities 3 — Questions and Answers
Question 1: What is the relationship between Microsoft Sentinel and Azure Log Analytics?
- They are completely independent products with no shared infrastructure
- Microsoft Sentinel is built on top of Azure Log Analytics workspaces (Correct answer)
- Azure Log Analytics is a feature within Microsoft Sentinel
- They share only a billing system
Correct answer: Microsoft Sentinel is built on top of Azure Log Analytics workspaces
Microsoft Sentinel is built on Azure Log Analytics, using the Log Analytics workspace as its underlying data store for all ingested security data.
Question 2: What does SOAR stand for in the context of Microsoft Sentinel?
- Security Operations and Automated Reporting
- Security Orchestration, Automation, and Response (Correct answer)
- Synchronized Operations, Analytics, and Remediation
- Security Oversight, Alerting, and Review
Correct answer: Security Orchestration, Automation, and Response
SOAR stands for Security Orchestration, Automation, and Response, and Microsoft Sentinel's playbook functionality provides SOAR capabilities.
Question 3: Which Microsoft Sentinel feature leverages AI and machine learning to detect anomalies without pre-written rules?
- Scheduled analytics rules
- Fusion detection (Correct answer)
- Workbooks
- Data connectors
Correct answer: Fusion detection
Microsoft Sentinel's Fusion detection uses machine learning to correlate low-fidelity signals across multiple data sources to detect multi-stage attack scenarios.
Question 4: What is the purpose of Incidents in Microsoft Sentinel?
- To schedule automated playbooks
- To group related alerts into a single actionable investigation case (Correct answer)
- To ingest data from third-party connectors
- To define KQL-based detection logic
Correct answer: To group related alerts into a single actionable investigation case
Incidents in Microsoft Sentinel aggregate related alerts into a single case, providing analysts with a unified view for investigating a potential attack.
Question 5: Which built-in role grants read-only access to Microsoft Sentinel data, workbooks, and incidents?
- Microsoft Sentinel Contributor
- Microsoft Sentinel Responder
- Microsoft Sentinel Reader (Correct answer)
- Log Analytics Reader
Correct answer: Microsoft Sentinel Reader
The Microsoft Sentinel Reader role allows users to view data, incidents, workbooks, and other Sentinel resources without the ability to make changes.
Question 6: What does Microsoft Sentinel's User and Entity Behavior Analytics (UEBA) feature do?
- Blocks user accounts automatically when anomalies are detected
- Builds baseline behavioral profiles to detect anomalous user and entity activities (Correct answer)
- Manages multi-factor authentication policies
- Generates compliance reports for regulatory audits
Correct answer: Builds baseline behavioral profiles to detect anomalous user and entity activities
UEBA in Microsoft Sentinel analyzes user and entity behavior over time to build baselines and then flags deviations that may indicate insider threats or compromised accounts.
Question 7: How does Microsoft Sentinel reduce alert fatigue for security operations teams?
- By limiting the number of data connectors that can be used
- By correlating alerts into incidents and using ML to prioritize high-fidelity detections (Correct answer)
- By requiring manual approval before any alert is created
- By only ingesting data from Microsoft products
Correct answer: By correlating alerts into incidents and using ML to prioritize high-fidelity detections
Microsoft Sentinel reduces alert fatigue by using machine learning to correlate related alerts into incidents and suppress low-fidelity noise, helping analysts focus on real threats.
What is the relationship between Microsoft Sentinel and Azure Log Analytics?