FEFreeExamDumps.in

Microsoft Security Operations Analyst

Topic 1

Question 17

SC-200 voucher + Udemy course (lifetime access) = ₹3,500 for Indian ID card holders.

Details →

You have a third-party security information and event management (SIEM) solution. You need to ensure that the SIEM solution can generate alerts for Azure Active Directory (Azure AD) sign-events in near real time. What should you do to route events to the SIEM solution?

  • ACreate an Azure Sentinel workspace that has a Security Events connector.
  • BConfigure the Diagnostics settings in Azure AD to stream to an event hub.
  • CCreate an Azure Sentinel workspace that has an Azure Active Directory connector.
  • DConfigure the Diagnostics settings in Azure AD to archive to a storage account.