Microsoft SC-200 Hunting Graphs Blast RADIUS And Sentinel Graph Practice Test
Skills 3.1 • 30 original questions
This Microsoft SC-200 Security Operations Analyst practice test focuses on hunting graphs blast radius and sentinel graph through original scenario-based questions aligned to the skills measured as of July 28, 2026. Use the full ExamSnap SC-200 collection for broader practice across the current Defender XDR, Microsoft Sentinel, incident-response, and threat-hunting skill areas. For broader exam preparation, review the Microsoft SC-200 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a ransomware response at Fabrikam Retail, the SOC analyst must visualize connected entities and estimate the blast radius of the suspected attack. Which action most directly satisfies the requirement for the identity-response team, response wave 1? The design priority is to preserve investigation context.
Correct answer: C
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
Adventure Works is revising its SOC runbook after a threat-hunting campaign. Analysts need to analyze relationships among security entities by using the Sentinel graph view. Which implementation should the Defender administrator select for the endpoint-response team, response wave 1 while trying to minimize manual analyst steps?
Correct answer: C
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
D: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
A ticket escalated to the threat hunter at Alpine Ski House states one non-negotiable goal: visualize connected entities and estimate the blast radius of the suspected attack. Which choice is the strongest fit for the messaging-security team, response wave 2? The team also wants to minimize manual analyst steps.
Correct answer: C
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
For the night shift, response wave 2 at Wide World Importers, a post-incident review can proceed only if the team can analyze relationships among security entities by using the Sentinel graph view. What should the SOC analyst configure first if the operational goal is to retain evidence for follow-up analysis?
Correct answer: D
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
The security architecture review at Lucerne Publishing focuses on this requirement: visualize connected entities and estimate the blast radius of the suspected attack. Which Microsoft security action is most appropriate for the Americas SOC, response wave 3, given the need to retain evidence for follow-up analysis?
Correct answer: D
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
A change advisory board at Northwind Traders asks how to analyze relationships among security entities by using the Sentinel graph view during a detection-engineering sprint. Which proposed action should the threat hunter approve for the high-value-assets group, response wave 3? The change should avoid unnecessary alert noise.
Correct answer: D
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
Woodgrove Bank has ruled out a manual one-off workaround. For the server fleet, response wave 4, the remaining requirement is to visualize connected entities and estimate the blast radius of the suspected attack. Which choice best addresses it and helps avoid unnecessary alert noise?
Correct answer: C
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
During post-incident review at Blue Yonder Airlines, the Tier 2 analyst identifies a gap: the SOC still needs to analyze relationships among security entities by using the Sentinel graph view. Which action should be added for the remote-user fleet, response wave 4 before the next incident, with an emphasis on trying to preserve least privilege?
Correct answer: A
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
The Sentinel administrator at A. Datum is comparing several Microsoft security options for a audit investigation. Which one directly enables the team to visualize connected entities and estimate the blast radius of the suspected attack for the research subscription, response wave 5 while helping preserve least privilege?
Correct answer: A
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
A security-operations workshop at Contoso Health defines the desired outcome as follows: analyze relationships among security entities by using the Sentinel graph view. Which implementation should be chosen for the regulated workload segment, response wave 5? The team wants to reduce mean time to respond.
Correct answer: D
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
Which Microsoft security action best matches this technical purpose for the Tier 2 queue, response wave 6: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. The SOC is trying to reduce mean time to respond.
Correct answer: B
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
An analyst at Proseware Services describes the needed capability this way: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. Which option should be associated with that requirement for the identity-response team, response wave 6 while the team tries to scope the change to the affected security domain?
Correct answer: E
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
During a design validation for the cloud-security team, response wave 7, Wide World Importers documents the following behavior: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. Which Microsoft security feature or action is being described? The objective is to scope the change to the affected security domain.
Correct answer: D
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
The security operations analyst must identify the Microsoft security capability that provides this function for the messaging-security team, response wave 7: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. Which choice is correct if the SOC also needs to keep the workflow auditable?
Correct answer: B
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
A runbook for the EMEA SOC, response wave 8 contains this description: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. Which implementation belongs in that runbook during a multi-cloud monitoring rollout? The process should keep the workflow auditable.
Correct answer: A
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
Tailspin Toys is troubleshooting a ransomware response. Evidence shows that the decisive requirement is to analyze relationships among security entities by using the Sentinel graph view. Which action should the incident responder investigate first for the Americas SOC, response wave 8, without losing the ability to avoid changing an unrelated control plane?
Correct answer: B
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
After eliminating network and licensing causes, the SOC analyst at Blue Yonder Airlines determines that success depends on the ability to visualize connected entities and estimate the blast radius of the suspected attack. Which security action should be checked next for the privileged-users group, response wave 9? The team must avoid changing an unrelated control plane.
Correct answer: B
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
A service-desk escalation during a phishing investigation has been narrowed to one security-operations requirement: analyze relationships among security entities by using the Sentinel graph view. Which configuration is the most relevant starting point for the server fleet, response wave 9 if the SOC wants to improve detection coverage?
Correct answer: D
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
E: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
The failure pattern at Contoso Health affects the production subscription, response wave 10. Before making unrelated policy changes, the threat hunter needs a solution that will visualize connected entities and estimate the blast radius of the suspected attack. Which action is most directly relevant and helps improve detection coverage?
Correct answer: B
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
While investigating a SOC handoff review, Litware Manufacturing confirms the environment must analyze relationships among security entities by using the Sentinel graph view. Which Microsoft security capability should be validated for the research subscription, response wave 10? The investigation should support repeatable response.
Correct answer: E
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
Two teams at Proseware Services propose different approaches for the Tier 1 queue, response wave 11. The selection criterion is simple: the chosen approach must visualize connected entities and estimate the blast radius of the suspected attack. Which option should win the technical comparison if the SOC also wants to support repeatable response?
Correct answer: D
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
For the Tier 2 queue, response wave 11, Fourth Coffee wants the least indirect solution to this goal: analyze relationships among security entities by using the Sentinel graph view. Which action aligns most closely with that requirement and the need to separate collection from detection logic?
Correct answer: B
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
C: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
A modernization plan at Wingtip Toys includes a detection-engineering sprint. The security engineer is asked to choose the control that specifically helps the organization visualize connected entities and estimate the blast radius of the suspected attack. Which choice fits best for the endpoint-response team, response wave 12 while supporting the goal to separate collection from detection logic?
Correct answer: A
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
The cloud-security team, response wave 12 is moving into a controlled rollout at Fabrikam Retail. Which action should be included when the stated security objective is to analyze relationships among security entities by using the Sentinel graph view? The operational standard is to preserve investigation context.
Correct answer: D
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
Tailspin Toys is replacing an ad hoc process during a data-ingestion rollout. The replacement must reliably visualize connected entities and estimate the blast radius of the suspected attack. Which security-operations approach should the Sentinel administrator implement for the night shift, response wave 13 if the team also wants to preserve investigation context?
Correct answer: E
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
An audit finding for the EMEA SOC, response wave 13 says the current process does not consistently analyze relationships among security entities by using the Sentinel graph view. Which Microsoft security action most directly closes that gap while helping the SOC minimize manual analyst steps?
Correct answer: A
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
The security operations analyst at Trey Research needs a repeatable configuration for the high-value-assets group, response wave 14. It must visualize connected entities and estimate the blast radius of the suspected attack. Which choice should be implemented instead of relying on manual incident work if the goal is to minimize manual analyst steps?
Correct answer: A
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
During readiness testing at Lucerne Publishing, the privileged-users group, response wave 14 fails a business requirement because analysts cannot yet analyze relationships among security entities by using the Sentinel graph view. Which action should be implemented before rollout continues? The SOC also needs to retain evidence for follow-up analysis.
Correct answer: C
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: Threat analytics provides curated intelligence and organizational exposure context so analysts can understand relevant campaigns and prioritize mitigation. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
A governance review asks the incident responder to justify the control selected for the remote-user fleet, response wave 15. The requirement is to visualize connected entities and estimate the blast radius of the suspected attack. Which action has the clearest technical alignment while supporting the goal to retain evidence for follow-up analysis?
Correct answer: A
Why: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Option review:
A: Hunting graphs help analysts reason about entity relationships and visualize how an attack may have spread across connected assets. This directly addresses the requirement: visualize connected entities and estimate the blast radius of the suspected attack.
B: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
C: KQL jobs in the Sentinel Data Lake support scheduled or managed processing over data retained in the lake and are appropriate when the hunt depends on data-lake scale or history. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
D: Summary rules pre-aggregate selected data into tables that can improve query performance and make recurring analytical patterns easier to query. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
E: Sentinel hunting queries support repeatable proactive searches across the workspace and can be monitored as the analyst develops and refines the hunting hypothesis. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: visualize connected entities and estimate the blast radius of the suspected attack.
Learning point: Create or use the hunting graph to visualize connected entities and assess the incident blast radius
For a multi-cloud monitoring rollout, Woodgrove Bank needs a Microsoft security capability with this effect: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. Which option most accurately provides that capability for the production subscription, response wave 15? The process should avoid unnecessary alert noise.
Correct answer: E
Why: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Option review:
A: KQL is the query language used to analyze large security datasets and supports filtering, aggregation, parsing, joins, and time-based correlation for threat hunting. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
B: Sentinel notebooks support programmable investigation and hunting workflows, including data science and AI-assisted integrations such as the Sentinel MCP Server. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
C: Effective KQL hunting starts with the correct table because device, identity, email, cloud, and other event families are stored in different schemas. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
D: Advanced Hunting provides cross-domain Defender data that can be queried with KQL to test hypotheses and investigate suspicious activity across supported entities. It can be appropriate in another security-operations scenario, but it does not most directly address this requirement: analyze relationships among security entities by using the Sentinel graph view.
E: Sentinel Graph exposes entity relationships so analysts can pivot through connections that are difficult to understand from isolated log rows. This directly addresses the requirement: analyze relationships among security entities by using the Sentinel graph view.
Learning point: Use Sentinel Graph to explore relationships between the relevant security entities
Popular posts
Recent Posts
