Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelEasy

A security analyst is investigating a high-severity incident in Microsoft Sentinel. The analyst needs to quickly understand the relationships between various entities involved, such as compromised users, affected hosts, and suspicious IP addresses, to visualize the attack chain. Which Sentinel feature is designed to provide this graphical representation?

  1. AWorkbooks
  2. BPlaybooks
  3. CHunting queries
  4. DInvestigation graph
Show answer & explanation

Correct answer: D. Investigation graph

The Investigation graph in Microsoft Sentinel provides a visual, interactive representation of entities related to an incident, allowing analysts to explore connections and uncover the full scope of an attack.

Why the other options are wrong

  • A. Workbooks are interactive dashboards for data visualization and monitoring, not specifically for incident investigation graphs.
  • B. Playbooks are automated response actions, not a tool for graphical investigation.
  • C. Hunting queries are used for proactive threat discovery, not for visualizing relationships within an existing incident.

Microsoft Sentinel Investigation Graph

A visual tool within Microsoft Sentinel incidents that displays the relationships between different entities (users, hosts, IPs, etc.) and alerts involved in an incident.

  • Helps analysts understand the scope and impact of an attack.
  • Provides an interactive timeline and entity details.
  • Facilitates pivoting between related entities for deeper analysis.

Memory trick: Think of the Investigation Graph as the 'detective's corkboard' where all clues are connected.

More Mitigate threats using Microsoft Sentinel questions