SC-200 · Question #61
You have an Azure subscription that has Azure Defender enabled for all supported resource types. You need to configure the continuous export of high-severity alerts to enable their retrieval from a…
The correct answer is C. Azure Event Hubs. Continuous export lets you fully customize what will be exported, and where it will go. For example, you can configure it so that: All high severity alerts are sent to an Azure Event Hub All medium or higher severity findings from vulnerability assessment scans of your SQL…
Question
You have an Azure subscription that has Azure Defender enabled for all supported resource types. You need to configure the continuous export of high-severity alerts to enable their retrieval from a third-party security information and event management (SIEM) solution. To which service should you export the alerts?
Options
- AAzure Cosmos DB
- BAzure Event Grid
- CAzure Event Hubs
- DAzure Data Lake
How the community answered
(32 responses)- A3% (1)
- B9% (3)
- C72% (23)
- D16% (5)
Explanation
Continuous export lets you fully customize what will be exported, and where it will go. For example, you can configure it so that: All high severity alerts are sent to an Azure Event Hub All medium or higher severity findings from vulnerability assessment scans of your SQL servers are sent to a specific Log Analytics workspace Specific recommendations are delivered to an Event Hub or Log Analytics workspace whenever they're generated The secure score for a subscription is sent to a Log Analytics workspace whenever the score for a control changes by 0.01 or more https://docs.microsoft.com/en-us/azure/security-center/continuous-export?tabs=azure-portal
Topics
Community Discussion
No community discussion yet for this question.