SC-200 · Question #113
You have an Azure subscription named Sub1 and a Microsoft 365 subscription. Sub1 is linked to an Azure Active Directory (Azure AD) tenant named contoso.com. You create an Azure Sentinel workspace…
The correct answer is C. Create a Microsoft Cloud App Security connector. D. Create an Azure AD Identity Protection connector. The Fusion rule in Azure Sentinel uses machine learning to correlate signals from multiple data sources to detect multi-stage attacks. For the specific scenario of suspicious Azure AD sign-ins followed by anomalous Office 365 activity, Fusion requires two specific connectors…
Question
You have an Azure subscription named Sub1 and a Microsoft 365 subscription. Sub1 is linked to an Azure Active Directory (Azure AD) tenant named contoso.com. You create an Azure Sentinel workspace named workspace1. In workspace1, you activate an Azure AD connector for contoso.com and an Office 365 connector for the Microsoft 365 subscription. You need to use the Fusion rule to detect multi-staged attacks that include suspicious sign-ins to contoso.com followed by anomalous Microsoft Office 365 activity. Which two actions should you perform? Each correct answer present part of the solution. NOTE: Each correct selection is worth one point.
Options
- ACreate custom rule based on the Office 365 connector templates.
- BCreate a Microsoft incident creation rule based on Azure Security Center.
- CCreate a Microsoft Cloud App Security connector.
- DCreate an Azure AD Identity Protection connector.
How the community answered
(67 responses)- A16% (11)
- B7% (5)
- C76% (51)
Explanation
The Fusion rule in Azure Sentinel uses machine learning to correlate signals from multiple data sources to detect multi-stage attacks. For the specific scenario of suspicious Azure AD sign-ins followed by anomalous Office 365 activity, Fusion requires two specific connectors: (D) the Azure AD Identity Protection connector, which surfaces risky and suspicious sign-in events from Azure AD, and (C) the Microsoft Cloud App Security connector, which detects anomalous behavior across Office 365 and other cloud apps. Without both connectors active, Fusion cannot correlate signals across the two stages of this attack pattern. Options A and B reference Azure Security Center and custom Office 365 templates, which are unrelated to this Fusion detection scenario.
Topics
Community Discussion
No community discussion yet for this question.