SC-200 · Question #220
You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You need to ensure that you can investigate threats by using data in the unified audit log of Microsoft Defender for Cloud…
The correct answer is C. the Office 365 connector. The unified audit log is a Microsoft 365 (Office 365) feature that records user and admin activity across Microsoft 365 services. To make this audit log data available within Microsoft Defender for Cloud Apps for threat investigation, you must first configure the Office 365…
Question
You have a Microsoft 365 E5 subscription that uses Microsoft Defender 365. You need to ensure that you can investigate threats by using data in the unified audit log of Microsoft Defender for Cloud Apps. What should you configure first?
Options
- Athe User enrichment settings
- Bthe Azure connector
- Cthe Office 365 connector
- Dthe Automatic log upload settings
How the community answered
(31 responses)- A13% (4)
- B6% (2)
- C77% (24)
- D3% (1)
Explanation
The unified audit log is a Microsoft 365 (Office 365) feature that records user and admin activity across Microsoft 365 services. To make this audit log data available within Microsoft Defender for Cloud Apps for threat investigation, you must first configure the Office 365 connector. This connector establishes the integration between Defender for Cloud Apps and the Microsoft 365 unified audit log, enabling activity data ingestion. The Azure connector integrates Azure services (not the audit log), Automatic log upload is for firewall/proxy traffic logs, and User enrichment settings enhance user profile data - none of these provide access to the unified audit log.
Topics
Community Discussion
No community discussion yet for this question.