SC-900 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Sentinel Capabilities 4 — Questions and Answers
Question 1: Which pricing model does Microsoft Sentinel use for data ingestion?
- A flat monthly fee regardless of data volume
- Pay-as-you-go based on GB of data ingested, or commitment tiers (Correct answer)
- A per-user licensing model
- Free for all Azure customers with no additional cost
Correct answer: Pay-as-you-go based on GB of data ingested, or commitment tiers
Microsoft Sentinel uses a consumption-based pricing model where organizations pay per GB of data ingested, with commitment tiers available for predictable workloads.
Question 2: What is the Microsoft Sentinel Content Hub?
- A marketplace for purchasing third-party security tools
- A central location to discover and deploy packaged solutions including connectors, rules, and workbooks (Correct answer)
- A repository for storing raw log data
- An external threat intelligence sharing platform
Correct answer: A central location to discover and deploy packaged solutions including connectors, rules, and workbooks
The Microsoft Sentinel Content Hub is a centralized marketplace where organizations can find and deploy out-of-the-box solutions that include data connectors, analytics rules, and workbooks for specific products.
Question 3: Which Microsoft Sentinel capability allows analysts to collaborate on investigations and document findings in a shared space?
- Watchlists
- Notebooks (Correct answer)
- Playbooks
- Analytics rules
Correct answer: Notebooks
Microsoft Sentinel Notebooks, powered by Jupyter Notebooks, allow analysts to document investigations, run advanced queries, and collaborate using a shareable interactive environment.
Question 4: What type of threat intelligence can be imported into Microsoft Sentinel to enhance detections?
- Only Microsoft's own threat intelligence feed
- Indicators of Compromise (IOCs) such as malicious IPs, URLs, and file hashes from TAXII or STIX feeds (Correct answer)
- Only antivirus signature databases
- Performance benchmarks from industry standards bodies
Correct answer: Indicators of Compromise (IOCs) such as malicious IPs, URLs, and file hashes from TAXII or STIX feeds
Microsoft Sentinel can ingest threat intelligence data in STIX/TAXII format, including IOCs like malicious IPs, domains, and file hashes, which are used to enrich analytics rules.
Question 5: What is the role of the Microsoft Sentinel Contributor RBAC role?
- View-only access to Sentinel data and incidents
- Full administrative control including billing and subscription management
- Create and edit workbooks, analytics rules, playbooks, and manage incidents (Correct answer)
- Only the ability to run playbooks on existing incidents
Correct answer: Create and edit workbooks, analytics rules, playbooks, and manage incidents
The Microsoft Sentinel Contributor role allows users to create and edit workbooks, analytics rules, playbooks, and other Sentinel resources, as well as manage incidents.
Question 6: Which feature in Microsoft Sentinel maps detected threats to the MITRE ATT&CK framework?
- Workbooks
- MITRE ATT&CK coverage view in Analytics and Threat Intelligence (Correct answer)
- Data connectors dashboard
- Fusion rules
Correct answer: MITRE ATT&CK coverage view in Analytics and Threat Intelligence
Microsoft Sentinel includes a MITRE ATT&CK framework view in the Analytics section that maps your enabled detection rules to specific tactics and techniques to show coverage.
Question 7: In Microsoft Sentinel, what is the difference between an alert and an incident?
- Alerts are created manually while incidents are automated
- An alert is a single detection event; an incident groups one or more related alerts for investigation (Correct answer)
- Incidents are low severity and alerts are high severity
- There is no difference — the terms are interchangeable in Sentinel
Correct answer: An alert is a single detection event; an incident groups one or more related alerts for investigation
An alert is an individual detection from an analytics rule, while an incident is a grouped collection of related alerts that together form an investigation case for analysts.
Which pricing model does Microsoft Sentinel use for data ingestion?