Which role provides permissions to view data, incidents, workbooks, and all Azure Sentinel resources?
Which role provides permissions to view data, incidents, workbooks, and all Azure Sentinel resources?
The Azure Sentinel Reader role has permissions to view data, incidents, workbooks, and all Azure Sentinel resources.
Which role provides the ability to manage incidents?
Which role provides the ability to manage incidents?
The Azure Sentinel Responder role has all the permissions of Azure Sentinel Reader plus the ability to manage incidents.
Which role provides permissions to read, write, and delete all Azure Sentinel related resources. This role will provide the permissions to create and edit workbooks?
Which role provides permissions to read, write, and delete all Azure Sentinel related resources. This role will provide the permissions to create and edit workbooks?
The Azure Sentinel Contributor role has permissions to read, write, and delete all Azure Sentinel related resources. This role Will provide the permissions to create and edit workbooks.
Which Azure Sentinel role provides permissions to be able to configure a playbook, and create a Logic App?
Which Azure Sentinel role provides permissions to be able to configure a playbook, and create a Logic App?
The Azure Sentinel Contributor role provides permissions to configure a playbook and Logic App Contributor role provides permissions to create a Logic App.
Azure Sentinel Incident Owner
Azure Sentinel Incident Owner
The incident detailed information includes its severity, summary of the number of entities involved, the raw events that triggered this incident, and the incident’s unique ID. All incidents start as unassigned. For each incident you can assign an owner, by setting the Incident owner field. You can also add comments so that other analysts will be able to understand what you investigated and what your concerns are around the incident.
Azure Sentinel Build-in Roles
Azure Sentinel Build-in Roles
The Sentinel built-in roles are reader, responder, and contributor.
There is no owner role.
Azure Sentinel Notebook
Azure Sentinel Notebook
A notebook is a step-by-step playbook where you can walk through to the steps of an investigation and hunt. Other hunting techniques are described by the other choices: built-in query, bookmarks, and event tables.
Azure Security Center Dashboard Secure Score
Azure Security Center Dashboard Secure Score
The Secure Score is a calculation based on the ratio of healthy resources vs. total resources. Security Center reviews your security recommendations across all workloads, uses algorithms to determine how critical each recommendation is, and calculates a Secure Score which is displayed on the Overview page.
Two fundamental data types that Azure Monitor uses?
Two fundamental data types that Azure Monitor uses? Metrics and Logs.

Processed events that Azure Security Center produces are published to …
Processed events that Azure Security Center produces are published to the Azure activity log, one of the log types available through Azure Monitor.
What is used to stream log data from Azure Monitor to Azure Sentinel or a partner SIEM and monitoring tools?
What is used to stream log data from Azure Monitor to Azure Sentinel or a partner SIEM and monitoring tools?
Event Hubs
Stream log data from Azure Monitor to Azure Sentinel or a partner SIEM and monitoring tools. What are the tiers of monitoring data that can be sent to the Event Hub?
Stream log data from Azure Monitor to Azure Sentinel or a partner SIEM and monitoring tools. What are the tiers of monitoring data that can be sent to the Event Hub?
What connectors does Azure Sentinel come with out of the box and provide real-time integration?
What connectors does Azure Sentinel come with out of the box and provide real-time integration?
Where does Azure Security Center store data that it collects?
Where does Azure Sentinel store data from data sources?
Where does Azure Security Center store data that it collects?
Log Analytics Workspace (LAW) where it can be analyzed with other log data.
Where does Azure Sentinel store data from data sources?
Log Analytics Workspace (LAW)
What are the ways you can start Log Analytics?
What are the ways you can start Log Analytics?
Note: The scope of the data available depends on how you start it.