While threat hunting in Microsoft Sentinel, you run a KQL query that identifies suspicious PowerShell download activity on five hosts. You want to preserve each finding with its associated entities and then open a single case that groups all of them for the incident response team. What two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: From the Hunting results, select each row and add a bookmark with relevant tags and entity mappings., From the Bookmarks pane, select the created bookmarks and choose Create incident to generate one incident containing them..
Why this is the answer
To preserve individual findings from a KQL query and group them into a single incident, you should first create bookmarks. Bookmarks allow you to save specific query results, associate them with relevant entities (like hosts and users), and add tags for better organization. After creating a bookmark for each suspicious activity, you can then select these multiple bookmarks from the Bookmarks pane and choose the "Create incident" option. This action consolidates all the bookmarked findings into a single incident, streamlining the investigation for the incident response team. Exporting to CSV and attaching to an ITSM ticket bypasses Sentinel's incident management capabilities. Saving as a scheduled analytics rule is for future detection, not preserving current findings. Adding hosts to a watchlist doesn't automatically create incidents for past activities.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed