Leadership asks the SOC lead to show which MITRE ATT&CK tactics and techniques are currently covered by enabled detections in their Microsoft Sentinel workspace, and to identify gaps where no active analytics rule maps to a technique. Which Microsoft Sentinel capability presents this coverage view directly?
- AThe Workbooks gallery, which visualises ingested log volume per connected data source over time
- BThe MITRE ATT&CK coverage page, which colours the matrix by enabled analytics rules and hunting queries Correct
- CThe Threat intelligence page, which lists imported indicators grouped by the tactic they relate to
- DThe Entity behaviour page, which scores users and hosts against learned behavioural baselines
Why A is wrong: Workbooks chart operational metrics such as ingestion volume; while customisable, the gallery does not provide the built-in technique-by-rule coverage mapping that the request needs.
Why B is correct: The MITRE ATT&CK page in Sentinel overlays the matrix with the tactics and techniques covered by active rules and hunting queries, exposing coverage and gaps at a glance.
Why C is wrong: The threat intelligence page manages indicators of compromise, not detection coverage, so it cannot map enabled analytics rules onto the ATT&CK matrix to reveal gaps.
Why D is wrong: Entity behaviour focuses on per-entity risk from behavioural analytics; it does not enumerate which ATT&CK techniques your enabled rules detect or where coverage is missing.