Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security analyst is investigating a complex incident in Microsoft Sentinel involving multiple alerts from different data sources, including Azure Active Directory, Microsoft 365 Defender, and a custom firewall. The analyst needs to understand the relationships between various entities (users, devices, IPs) and the sequence of events that led to the incident. Which Microsoft Sentinel feature is specifically designed to visually represent these connections and aid in the investigation?
- AWorkbooks
- BInvestigation Graph
- CHunting Queries
- DAnalytics Rules
Show answer & explanationAnswer & explanation
Correct answer: B. Investigation Graph
The Investigation Graph in Microsoft Sentinel provides a visual, interactive representation of entities and their relationships within an incident, making it easier to understand complex attack chains and connections.
Why the other options are wrong
- A. Workbooks are for data visualization and dashboards, not for interactive incident investigation graphs.
- C. Hunting Queries are for proactive threat discovery, not for visualizing relationships within an existing incident.
- D. Analytics Rules are for detecting threats and generating incidents, not for post-incident visualization of relationships.
Microsoft Sentinel Investigation Graph
The Investigation Graph in Microsoft Sentinel is a visual tool that helps security analysts understand the relationships between different entities (users, hosts, IP addresses, etc.) involved in an incident.
- Interactive visual representation of incident entities.
- Helps identify scope and root cause.
- Reveals connections between alerts and events.
Memory trick: Graph Guides Global Incident Understanding