Microsoft Certified Azure Security Engineer Associate · Free Practice Question Medium
Question 5
You are asked to set up a monitoring solution for security events in your Azure environment. You decide to leverage Azure Monitor and Microsoft Sentinel. Which of the following actions would you take for a holistic monitoring solution?
-
A
Use Azure Monitor to collect data on application performance
-
B
Configure data connectors in Microsoft Sentinel to integrate various data sources
-
C
Create and customize analytics rules in Microsoft Sentinel to detect specific patterns
-
D
Modify Microsoft Defender for Cloud to integrate with Azure Monitor
-
E
Configure Data Collection
Reveal correct answers
Correct answers: B, C, E
Explanation
Microsoft Sentinel provides data connectors to connect with various data sources: for security event collection, making it a critical component of the monitoring solution.
Customized analytics rules in Microsoft Sentinel allow you to specify detection patterns: for making it another essential part of a security monitoring solution.
Configure Data Collection: Ensure that Azure Monitor is configured to collect logs and metrics from all relevant Azure resources, such as Virtual Machines, Azure Active Directory, and Azure services
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
