In your Microsoft Sentinel workspace, analysts report many separate incidents generated from the same host during a 24-hour brute-force campaign. They also want a fast way to visualize related alerts, users, hosts, and IPs tied to an incident. What two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Edit the analytics rule and enable alert grouping, grouping by key entities (such as host and user) over a 24-hour period to reduce incident sprawl., Open an incident and use the Investigation view to pivot through the investigation graph of related alerts, entities, and evidence..
Why this is the answer
To address the incident sprawl from a brute-force campaign, editing the analytics rule to enable alert grouping by key entities (like host and user) over a 24-hour period is crucial. This consolidates multiple related alerts into a single incident, making it easier for analysts to manage and investigate. For visualizing related alerts, users, hosts, and IPs, the Investigation view within an incident provides an interactive graph. This allows analysts to quickly pivot through connected entities and understand the scope of the attack. Reducing Log Analytics workspace retention or globally disabling incident creation for low-severity rules would hinder investigation and potentially miss critical events. Turning off entity mapping would prevent proper correlation and make incident analysis more difficult.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed