What is Azure Sentinel incident?

Experience Level: Junior
Tags: Azure CloudAzure Sentinel

Answer

Incidents are groups of related alerts that together create an actionable possible-threat that you can investigate and resolve. Use the built-in correlation rules as-is, or use them as a starting point to build your own.

Azure Sentinel also provides machine learning rules to map your network behavior and then look for anomalies across your resources. These analytics connect the dots, by combining low fidelity alerts about different entities into potential high-fidelity security incidents.

Related Azure Cloud job interview questions

Comments

No Comments Yet.
Be the first to tell us what you think.
Azure Sentinel
Azure Sentinel

Are you learning Azure Cloud ? Try our test we designed to help you progress faster.

Test yourself