SC-900 · Question #222
You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?
The correct answer is C. Connect to your data sources. After Microsoft Sentinel is enabled on a Log Analytics workspace, the first operational step is to connect data sources (also called connectors) so that Sentinel can ingest security data - logs from Azure services, Microsoft 365, third-party firewalls, SIEMs, and more. Without…
Question
You have an Azure subscription that contains a Log Analytics workspace. You need to onboard Microsoft Sentinel. What should you do first?
Options
- ACreate a hunting query.
- BCorrelate alerts into incidents.
- CConnect to your data sources.
- DCreate a custom detection rule.
How the community answered
(58 responses)- A2% (1)
- B3% (2)
- C86% (50)
- D9% (5)
Explanation
After Microsoft Sentinel is enabled on a Log Analytics workspace, the first operational step is to connect data sources (also called connectors) so that Sentinel can ingest security data - logs from Azure services, Microsoft 365, third-party firewalls, SIEMs, and more. Without data flowing in, there is nothing to analyze, correlate, or hunt through. Creating hunting queries (A) and custom detection rules (D) require data to already be present. Correlating alerts into incidents (B) is an automated process that happens after data and analytics rules are configured. Connecting data sources is the foundational prerequisite for everything else.
Topics
Community Discussion
No community discussion yet for this question.