A SOC team needs to detect risky sign-in behaviors (such as impossible travel) based on Azure AD sign-in logs and Microsoft 365 audit data, and to correlate endpoint alerts from Microsoft Defender for Endpoint. When a high-fidelity alert fires, the account should be disabled automatically and a ServiceNow incident opened. You are designing Microsoft Sentinel for this scenario. Which two configurations should you implement? Each correct answer presents part of the solution.
Choose an answer
Tap an option to check your answer.
Correct answer: Connect the built-in data connectors for Azure AD Sign-in Logs, Office 365, and Microsoft Defender for Endpoint to the Sentinel workspace., Create analytics rules (using scheduled or Microsoft security rule templates) to detect anomalies; attach a Logic Apps playbook that disables the account in Entra ID and creates a ServiceNow ticket..
Why this is the answer
The correct options directly address the requirements. Connecting the built-in data connectors for Azure AD Sign-in Logs, Office 365, and Microsoft Defender for Endpoint ensures that all necessary data sources (sign-in logs, audit data, endpoint alerts) are ingested into Sentinel for analysis. Creating analytics rules (scheduled or Microsoft security templates) allows for the detection of risky behaviors like impossible travel and correlation of alerts. Attaching a Logic Apps playbook to these rules enables the automated response of disabling the account and creating a ServiceNow incident, fulfilling the high-fidelity alert action. Incorrect options: Azure Automation runbooks can be used, but Logic Apps playbooks are the native and recommended way to automate responses in Sentinel, offering simpler integration and management. Installing a Syslog agent on domain controllers is unnecessary for Azure AD sign-in events, as these are collected directly via the Azure AD data connector. Syslog is typically for Linux/on-premises logs. Enabling UEBA (User and Entity Behavior Analytics) is beneficial but not sufficient on its own. It provides insights, but analytics rules are still needed to define specific detection logic and trigger automated responses based on high-fidelity alerts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed