Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security operations team is configuring Microsoft Sentinel to automatically enrich incidents with threat intelligence data from a custom feed. This enrichment should occur immediately after an incident is created and before any human intervention. Which Microsoft Sentinel feature should be used to achieve this?
- AHunting Queries
- BAnalytics Rules
- CWorkbooks
- DAutomation Rules
Show answer & explanationAnswer & explanation
Correct answer: D. Automation Rules
Automation rules in Microsoft Sentinel allow for immediate, automated actions on incidents, such as enrichment, based on predefined conditions. This ensures that incidents are processed without human intervention at the initial stage.
Why the other options are wrong
- A. Hunting Queries are for proactive threat discovery, not for automated incident response actions.
- B. Analytics Rules are used for detecting threats and generating incidents, not for enriching existing incidents.
- C. Workbooks are used for data visualization and reporting, not for automated incident enrichment.
Microsoft Sentinel Automation Rules
Automation rules in Microsoft Sentinel allow you to automate incident response actions, such as assigning incidents, changing their status, or running playbooks, based on specific conditions.
- Automate incident management tasks.
- Triggered by incident creation or updates.
- Can run playbooks for complex workflows.
Memory trick: Automate Actions for Alerted Incidents