MS-102 · Question #430
You have a Microsoft 365 tenant. You plan to manage incidents in the tenant by using the Microsoft Defender XDR. Which Microsoft service source will appear on the Incidents page of the Microsoft…
The correct answer is C. Microsoft Sentinel. The Microsoft Defender portal (defender.microsoft.com) supports a unified security operations experience, and Microsoft Sentinel incidents are surfaced directly on the Incidents page when Sentinel is connected to Defender XDR through the unified SOC platform integration. This…
Question
You have a Microsoft 365 tenant. You plan to manage incidents in the tenant by using the Microsoft Defender XDR. Which Microsoft service source will appear on the Incidents page of the Microsoft Defender portal?
Options
- AAzure Information Protection
- BAzure Web Application Firewall
- CMicrosoft Sentinel
- DMicrosoft Defender for Cloud Apps
How the community answered
(52 responses)- A8% (4)
- B4% (2)
- C71% (37)
- D17% (9)
Explanation
The Microsoft Defender portal (defender.microsoft.com) supports a unified security operations experience, and Microsoft Sentinel incidents are surfaced directly on the Incidents page when Sentinel is connected to Defender XDR through the unified SOC platform integration. This allows security teams to manage Sentinel incidents alongside native Defender incidents in one place. Azure Information Protection (A) and Azure Web Application Firewall (B) do not produce incidents surfaced on the Defender XDR Incidents page. Microsoft Defender for Cloud Apps (D) does feed alerts into Defender XDR incidents, but among the listed choices, Microsoft Sentinel (C) is the service that appears as a distinct service source on the Incidents page.
Topics
Community Discussion
No community discussion yet for this question.