Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
An organization is deploying Microsoft Defender for Endpoint across its network. They need to ensure that all security events and alerts generated by Defender for Endpoint are automatically forwarded to their existing Security Information and Event Management (SIEM) system for centralized logging, correlation, and long-term retention. Which integration method should be configured?
- AMicrosoft Sentinel data connector
- BMicrosoft Defender for Endpoint API
- CStreaming API for Microsoft Defender for Endpoint
- DMicrosoft Defender for Cloud Apps (MDCAS) integration
Show answer & explanationAnswer & explanation
Correct answer: C. Streaming API for Microsoft Defender for Endpoint
The Streaming API for Microsoft Defender for Endpoint is specifically designed to provide a continuous, near real-time stream of raw events and alerts to external systems like SIEMs, Azure Storage, or Event Hubs. This ensures all security data from Defender for Endpoint is available for centralized logging and analysis in the existing SIEM.
Why the other options are wrong
- A. A Microsoft Sentinel data connector is used to ingest MDE data *into* Sentinel, not to an external SIEM system.
- B. The general MDE API allows for programmatic access to data and actions but isn't the primary method for continuous event streaming to a SIEM.
- D. MDCAS is for cloud app security and has no direct role in streaming MDE endpoint events to an external SIEM.
MDE Streaming API
A feature in Microsoft Defender for Endpoint that provides a continuous stream of raw security events and alerts to external systems, such as SIEMs, data lakes, or Azure Event Hubs, for centralized logging and analysis.
- Enables near real-time data export.
- Used for integration with external SIEMs or data storage.
- Provides granular control over which event types are streamed.
Memory trick: Stream your MDE events to your SIEM lake.