nerdexam
Microsoft

SC-300 · Question #82

You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection policies enforced. You create an Azure Sentinel instance and configure the Azure Active Dir

The correct answer is C. Create an Azure Sentinel playbook.. Creating a Sentinel instance and configuring the Azure AD Connector = configuring the Azure AD connector within Sentinel settings, as detailed here: https://learn.microsoft.com/en- us/azure/sentinel/create-incidents-from-alerts

Submitted by lars.no· Mar 6, 2026Implement authentication and access management

Question

You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection policies enforced. You create an Azure Sentinel instance and configure the Azure Active Directory connector. You need to ensure that Azure Sentinel can generate incidents based on the risk alerts raised by Azure AD Identity Protection. What should you do first?

Options

  • AAdd an Azure Sentinel data connector.
  • BConfigure the Notify settings in Azure AD Identity Protection.
  • CCreate an Azure Sentinel playbook.
  • DModify the Diagnostics settings in Azure AD.

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    6% (3)
  • C
    76% (38)
  • D
    14% (7)

Explanation

Creating a Sentinel instance and configuring the Azure AD Connector = configuring the Azure AD connector within Sentinel settings, as detailed here: https://learn.microsoft.com/en- us/azure/sentinel/create-incidents-from-alerts

Topics

#Identity Protection#Azure Sentinel#risk alerts#security incidents

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice