Question 1
IntermediateManage incident response · Investigate and remediate incidents in Microsoft Sentinel
A security analyst at a retail company is investigating a Microsoft Sentinel incident that contains multiple alerts related to a single user account. The analyst needs to understand the full sequence of events, from a suspicious sign-in to potential data exfiltration, in a chronological order. Which Microsoft Sentinel feature provides a graphical timeline and allows the analyst to explore related entities for this purpose?
Answer and explanation
Correct answer: B
The Investigation Graph in Microsoft Sentinel is specifically designed to help analysts visualize and traverse the relationships between entities within an incident. It provides a timeline and an interactive map to understand the scope and sequence of an attack, making it the correct tool for this scenario. Workbooks are for visualization and reporting, Hunting is for proactive threat discovery, and Automation Rules are for automating responses.
