You are threat hunting suspicious traffic from a specific IP address. You nneed to annotate an intermediate event stored in the workspace and be able to reference the IP address when navigating through the investigation graph. What will you do?

Experience Level: Junior
Tags: Azure CloudAzure Sentinel

Answer

  • Go to Azure Sentinel
  • Go to Threat management - Hunting
  • Run the query
  • View the query results
  • Add bookmark
  • Map at least one entity type (either in Account, Host, IP address) - in this case, IP address will be the be right choice
  • Fill in Timestamp, tags and notes
  • Save the bookmark

Now the bookmarked data will be shared with other investigators.

Related Azure Cloud job interview questions

Comments

No Comments Yet.
Be the first to tell us what you think.
Azure Sentinel
Azure Sentinel

Are you learning Azure Cloud ? Try our test we designed to help you progress faster.

Test yourself
AZ-500 Microsoft Azure Security Technologies Preparation
AZ-500 Microsoft Azure Security Technologies Preparation

Are you learning Azure Cloud ? Try our test we designed to help you progress faster.

Test yourself