SC-900 · Question #189
You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?
The correct answer is C. Connect to your security sources. When onboarding Microsoft Sentinel to a Log Analytics workspace, the very first step is to connect your data sources (security sources) using data connectors. Sentinel is a SIEM that relies entirely on ingested log data to function - without connected sources, there is no data…
Question
You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?
Options
- ACreate a hunting query.
- BCorrelate alerts into incidents.
- CConnect to your security sources.
- DCreate a custom detection rule.
How the community answered
(50 responses)- A4% (2)
- B4% (2)
- C90% (45)
- D2% (1)
Explanation
When onboarding Microsoft Sentinel to a Log Analytics workspace, the very first step is to connect your data sources (security sources) using data connectors. Sentinel is a SIEM that relies entirely on ingested log data to function - without connected sources, there is no data to query, correlate, or detect threats against. All subsequent tasks - creating hunting queries (A), correlating alerts into incidents (B), and building custom detection rules (D) - are meaningless until data is flowing into the workspace.
Topics
Community Discussion
No community discussion yet for this question.