Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelEasy

A security operations center (SOC) manager wants to implement a solution in Microsoft Sentinel to automatically enrich incidents with threat intelligence data from a custom feed. This enrichment should occur immediately after an incident is created and before any human intervention. Which Microsoft Sentinel feature should the manager use?

  1. AAutomation rules
  2. BAnalytics rules
  3. CWorkbooks
  4. DHunting queries
Show answer & explanation

Correct answer: A. Automation rules

Automation rules in Microsoft Sentinel are designed to automatically perform actions on incidents, such as enriching them with external data, immediately after creation. This aligns perfectly with the requirement for immediate, pre-human intervention enrichment.

Why the other options are wrong

  • B. Analytics rules are used for detection and incident creation, not for post-creation enrichment.
  • C. Workbooks are used for data visualization and reporting, not for automated incident enrichment.
  • D. Hunting queries are used for proactive threat discovery, not for automated incident response actions.

Microsoft Sentinel Automation Rules

Automation rules in Microsoft Sentinel allow for automatic actions to be taken on incidents, such as assigning ownership, changing status, or triggering playbooks for enrichment or response.

  • Triggered by incident creation or update.
  • Can apply to specific incidents based on conditions.
  • Used to streamline incident response workflows.

Memory trick: Automated Rules: Your Incident's First Responder!

More Mitigate threats using Microsoft Sentinel questions