Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium
A Microsoft 365 administrator needs to integrate security alerts from Microsoft Defender XDR into their existing Security Information and Event Management (SIEM) system for centralized logging and analysis. The SIEM system supports ingesting data via an API endpoint that requires a continuous stream of security incidents and alerts. Which Microsoft Defender XDR integration method should the administrator choose?
- AMicrosoft Defender XDR Streaming API
- BEmail notification rules
- CManual export of incident reports
- DMicrosoft Defender XDR API for pulling alerts
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Defender XDR Streaming API
The Microsoft Defender XDR Streaming API is specifically designed for continuously exporting raw security events and alerts to external systems like SIEMs, providing a real-time data stream for comprehensive analysis.
Why the other options are wrong
- B. Email notification rules are suitable for alerting human operators but not for automated, structured data ingestion into a SIEM.
- C. Manual export is not scalable or automated for continuous real-time integration with a SIEM system.
- D. The Microsoft Defender XDR API for pulling alerts requires the SIEM to actively query for new alerts, which is less efficient for a continuous stream than a push-based streaming API.
Defender XDR Streaming API
The Microsoft Defender XDR Streaming API allows for the continuous export of raw security events, alerts, and incidents to Azure Storage, Azure Event Hubs, or other external systems like SIEMs.
- Provides near real-time data streaming.
- Enables integration with SIEMs, SOAR, and custom analytics solutions.
- Exports a rich set of data, including device, identity, and email events.
Memory trick: For a CONTINUOUS stream to a SIEM, you need the STREAMING API.