Chapter 10 – Using Azure Sentinel to Monitor Microsoft 365 Security
- a. True
Explanation: Azure Sentinel is capable of connecting to both Microsoft native, and third-party data sources
- c. Configuration | Playbooks
Explanation: Playbooks are configured in the Azure portal from the Configuration | Playbooks section
- d. Connect to a workspace
Explanation: Connecting to a workspace is the first task to complete. This must be done before you can setup a data connector, or create and connect to a playbook
- b. Contributor
Explanation: Contributor permissions are required to enable Azure Sentinel
- a. True
Explanation: N/A
- b. https://portal.azure.com
Explanation: Azure Sentinel must be setup from the Azure portal. There is no option to set up Azure Sentinel from the other listed portals
- b. False
Explanation: Azure Sentinel is a SIEM tool