Describe Microsoft Sentinel in a modern SOC
Microsoft Sentinel prepares a company to build a SOC that can focus on rapidly detecting, prioritizing, and triaging potential attacks. Companies that have a dedicated operations team that reviews events to identify and eliminate incidents that are false positives and be able to focus on real attacks. When you have a centralized security operations team, this team can monitor security-related data and investigate security breaches and threats. These teams work with other teams within an organization to communicate, investigate, and hunt activities that are aligned with the specific infrastructure or application teams.
Figure 11.19 provides a diagram of how an SOC team would respond to an incident:
The NIST Cybersecurity Framework provides guidance and best practices for aligning security functions within your operations. For information on the NIST Cybersecurity...