Q: 17
You need to collect and automatically analyze security events from Azure Active Directory (Azure
AD).
What should you use?
Options
Discussion
A or C but pretty sure it's A since Azure Sentinel is the SIEM tool for grabbing and analyzing AD logs. Not 100 percent though, anyone else see this on practice tests?
A is the way to go. Azure Sentinel pulls in security logs from Azure AD and automates the analysis, that's literally what it's built for. None of the others handle SIEM or analytics for AD events like Sentinel. Pretty sure on this one.
Be respectful. No spam.