nerdexam
Microsoft

SC-100 · Question #39

Your company has a third-party security information and event management (SIEM) solution that uses Splunk and Microsoft Sentinel. You plan to integrate Microsoft Sentinel with Splunk. You need to…

The correct answer is A. Azure Event Hubs. The correct answer is A: Azure Event Hubs. Microsoft Sentinel supports continuous export of security data (alerts, incidents, raw logs) to Azure Event Hubs. Splunk has a native Azure Event Hubs add-on that can consume events in real time from Event Hubs, enabling bidirectional…

Design security operations, identity, and compliance capabilities

Question

Your company has a third-party security information and event management (SIEM) solution that uses Splunk and Microsoft Sentinel. You plan to integrate Microsoft Sentinel with Splunk. You need to recommend a solution to send security events from Microsoft Sentinel to Splunk. What should you include in the recommendation?

Options

  • AAzure Event Hubs
  • BAzure Data Factor
  • Ca Microsoft Sentinel workbook
  • Da Microsoft Sentinel data connector

How the community answered

(13 responses)
  • A
    77% (10)
  • B
    8% (1)
  • C
    15% (2)

Explanation

The correct answer is A: Azure Event Hubs. Microsoft Sentinel supports continuous export of security data (alerts, incidents, raw logs) to Azure Event Hubs. Splunk has a native Azure Event Hubs add-on that can consume events in real time from Event Hubs, enabling bidirectional SIEM integration. This is the standard, documented integration pattern for connecting Microsoft Sentinel to Splunk. Azure Data Factory (B) is an ETL/data integration service suited for batch data movement, not real-time security event streaming. A Microsoft Sentinel workbook (C) is a visualization/reporting tool within Sentinel - it cannot export data to Splunk. A Microsoft Sentinel data connector (D) is used to ingest data INTO Sentinel from external sources, not to export data out of Sentinel.

Topics

#Microsoft Sentinel#SIEM integration#Azure Event Hubs#Security operations

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice