nerdexam
Microsoft

SC-900 · Question #189

You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?

The correct answer is C. Connect to your security sources. When onboarding Microsoft Sentinel to a Log Analytics workspace, the very first step is to connect your data sources (security sources) using data connectors. Sentinel is a SIEM that relies entirely on ingested log data to function - without connected sources, there is no data…

Submitted by satoshi_tk· Apr 18, 2026Describe the capabilities of Microsoft security solutions

Question

You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?

Options

  • ACreate a hunting query.
  • BCorrelate alerts into incidents.
  • CConnect to your security sources.
  • DCreate a custom detection rule.

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    4% (2)
  • C
    90% (45)
  • D
    2% (1)

Explanation

When onboarding Microsoft Sentinel to a Log Analytics workspace, the very first step is to connect your data sources (security sources) using data connectors. Sentinel is a SIEM that relies entirely on ingested log data to function - without connected sources, there is no data to query, correlate, or detect threats against. All subsequent tasks - creating hunting queries (A), correlating alerts into incidents (B), and building custom detection rules (D) - are meaningless until data is flowing into the workspace.

Topics

#Microsoft Sentinel#Onboarding#Data Connectors#SIEM

Community Discussion

No community discussion yet for this question.

Full SC-900 Practice