AZ-801 · Question #2
You are planning the deployment of Microsoft Sentinel. Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
The correct answer is D. Microsoft Defender for Identity. To collect security events and alerts related to identity threats for Microsoft Sentinel, the Microsoft Defender for Identity data connector should be used.
Question
Options
- AThreat Intelligence -TAXII
- BAzure Active Directory
- CMicrosoft Defender for Cloud
- DMicrosoft Defender for Identity
How the community answered
(48 responses)- A17% (8)
- B8% (4)
- C4% (2)
- D71% (34)
Why each option
To collect security events and alerts related to identity threats for Microsoft Sentinel, the Microsoft Defender for Identity data connector should be used.
Threat Intelligence - TAXII is used to import threat intelligence feeds into Sentinel, which is different from collecting security data from an identity protection service.
The Azure Active Directory data connector ingests audit logs, sign-in logs, and provisioning logs from Azure AD, which focuses on cloud identity, not specifically the advanced on-premises identity threat detection provided by Defender for Identity.
The Microsoft Defender for Cloud data connector ingests security alerts and recommendations from Defender for Cloud, which focuses on cloud resource security and workload protection, not specifically advanced on-premises identity threat detection.
The Microsoft Defender for Identity data connector integrates security alerts and raw activity data from Defender for Identity into Microsoft Sentinel. This is crucial for detecting and investigating advanced threats, compromised identities, and malicious insider actions within the on-premises Active Directory environment.
Concept tested: Microsoft Sentinel data connectors for identity protection
Source: https://learn.microsoft.com/en-us/azure/sentinel/data-connectors-reference#microsoft-defender-for-identity
Topics
Community Discussion
No community discussion yet for this question.