When planning the Microsoft Sentinel deployment to meet the security requirements, which type of Sentinel data connector should you choose?
Choose an answer
Tap an option to check your answer.
Correct answer: Microsoft Defender for Identity.
Why this is the answer
Microsoft Defender for Identity is the correct choice because it specifically monitors Active Directory Domain Services (AD DS) traffic and events, providing security insights into potential identity-based threats and anomalous user behavior. This directly addresses the need to meet security requirements related to identity protection within an Active Directory environment. Threat Intelligence - TAXII is used for importing threat intelligence feeds, which is a different security function. Azure Active Directory is a cloud identity service, distinct from on-premises AD DS monitoring. Microsoft Defender for Cloud focuses on cloud workload protection and security posture management across Azure, hybrid, and multi-cloud environments, not specifically on-premises AD DS traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed