You have an Azure Sentinel workspace. You need to manage incidents based on alerts generated by Microsoft Cloud App Security. What should you do first?
A.
From the Cloud App Security portal, configure security extensions.
B.
From the Cloud App Security portal, configure app connectors.
C.
From the Cloud App Security portal, configure log collectors.
D.
From the Microsoft 365 compliance center, add and configure a data connector.
Well, they are asking the question slightly differently – it should be the same though
4.80: You need to manage incidents based on alerts generated by Microsoft Defender for Cloud Apps
2.38: You need to manage incidents based on alerts generated by Microsoft Cloud App Security.
Integrating with Microsoft Sentinel
In the Defender for Cloud Apps portal, under the Settings cog, select Security extensions.
On the SIEM agents tab, select add (+), and then choose Microsoft Sentinel.
This section is not available anymore. Please use the main Exam Page.MS-500 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
pete26
Highly Voted 2 years, 8 months agomsysadmin
Most Recent 2 years, 3 months agoVJO
2 years, 7 months agoArmored5772
2 years, 9 months agopete26
2 years, 9 months agoheshmat2022
2 years, 9 months agoxyz213
2 years, 9 months ago