To access material, start machines and answer questions login.
Our Microsoft Sentinel journey continues. Let's take a quick snapshot of where we are in this journey and review the milestones we've passed in the previous rooms:
- Onboarding - Microsoft Sentinel concepts, planning and initial deployment
- Configuration - Installing Content hub solutions
- Configuration - Connecting Data connectors
- Threat detection - Analytics rules enabled
Learning Objectives
In this room, we will look into incident investigation and management concepts to see how we can easily manage security incidents in Microsoft Sentinel.
- Firstly, we'll introduce incident tools and features in Microsoft Sentinel
- Then, investigate sample incidents
- Finally, we'll see how we can manage incidents, hand them over, or escalate them a higher level security team
Prerequisites
A good understanding of previous Sentinel rooms is recommended to fully leverage the benefits of this room:
Ready to learn Cyber Security?
The MS Sentinel: Investigate room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in