nerdexam
Microsoft

SC-900 · Question #222

You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?

The correct answer is C. Connect to your data sources. After Microsoft Sentinel is enabled on a Log Analytics workspace, the first operational step is to connect data sources (also called connectors) so that Sentinel can ingest security data - logs from Azure services, Microsoft 365, third-party firewalls, SIEMs, and more. Without…

Submitted by the_admin· Apr 18, 2026Describe the capabilities of Microsoft security solutions

Question

You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?

Options

  • ACreate a hunting query.
  • BCorrelate alerts into incidents.
  • CConnect to your data sources.
  • DCreate a custom detection rule.

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    86% (50)
  • D
    9% (5)

Explanation

After Microsoft Sentinel is enabled on a Log Analytics workspace, the first operational step is to connect data sources (also called connectors) so that Sentinel can ingest security data - logs from Azure services, Microsoft 365, third-party firewalls, SIEMs, and more. Without data flowing in, there is nothing to analyze, correlate, or hunt through. Creating hunting queries (A) and custom detection rules (D) require data to already be present. Correlating alerts into incidents (B) is an automated process that happens after data and analytics rules are configured. Connecting data sources is the foundational prerequisite for everything else.

Topics

#Microsoft Sentinel#Onboarding#Data Connectors#SIEM

Community Discussion

No community discussion yet for this question.

Full SC-900 Practice