Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security engineer is planning the data ingestion for Microsoft Sentinel. The organization has a large number of Azure resources, including virtual machines, network security groups, and Azure Storage accounts, all generating diagnostic logs. The engineer wants to ensure that all these logs are ingested into Sentinel efficiently and cost-effectively, leveraging the native Azure integration. Which data connector type is best suited for collecting diagnostic logs from various Azure services?

  1. AAzure Active Directory connector
  2. BAzure Activity connector
  3. CSyslog connector
  4. DAzure Diagnostic Settings connector
Show answer & explanation

Correct answer: D. Azure Diagnostic Settings connector

Azure Diagnostic Settings allow you to configure specific Azure services (VMs, NSGs, Storage, etc.) to send their diagnostic logs and metrics to a Log Analytics workspace, which is the underlying data store for Sentinel.

Why the other options are wrong

  • A. Azure Active Directory connector specifically ingests AD audit and sign-in logs, not general Azure resource diagnostic logs.
  • B. Azure Activity connector ingests subscription-level events (control plane), not resource-specific diagnostic logs (data plane).
  • C. Syslog connector is for Linux-based systems and network devices, not native Azure service diagnostic logs.

Azure Diagnostic Settings

Azure Diagnostic Settings are used to configure an Azure resource to send its platform logs and metrics to one or more destinations, including a Log Analytics workspace (for Sentinel ingestion).

  • Configured per Azure resource (VM, NSG, Storage, etc.).
  • Sends resource-specific operational logs and metrics.
  • Essential for comprehensive Azure service monitoring in Sentinel.

Memory trick: Diagnostics Direct Data to Destination

More Mitigate threats using Microsoft Sentinel questions