Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard

A security architect is reviewing the current Microsoft Sentinel deployment and notices that a significant amount of data is being ingested from various Azure resources, but many of these logs are not contributing to any security detections or investigations. The architect wants to optimize ingestion costs by reducing unnecessary data. Which type of data ingestion method offers the most granular control over which specific log categories are collected from Azure resources?

  1. AAzure Activity connector
  2. BDiagnostic settings
  3. CMicrosoft 365 Defender connector
  4. DAzure Policy for Log Analytics
Show answer & explanation

Correct answer: B. Diagnostic settings

Diagnostic settings for Azure resources provide granular control over which log categories (e.g., 'Audit', 'SignInLogs', 'SecurityEvent') are sent to a Log Analytics workspace, allowing the architect to select only the relevant categories and reduce unnecessary ingestion.

Why the other options are wrong

  • A. The Azure Activity connector ingests subscription-level control plane events, but its granularity for specific log categories from individual resources is limited compared to diagnostic settings.
  • C. The Microsoft 365 Defender connector ingests data from various Defender products, but primarily at a suite level, not offering granular control over individual resource log categories.
  • D. Azure Policy can enforce diagnostic settings, but it's the diagnostic settings themselves that provide the granular control, not Azure Policy directly as an ingestion method.

Azure Diagnostic Settings

Azure Diagnostic Settings allow you to specify which log categories and metrics from individual Azure resources should be sent to a Log Analytics workspace (for Sentinel), event hub, or storage account, offering granular control over data ingestion.

  • Configured per Azure resource.
  • Selects specific log categories and metrics.
  • Crucial for cost optimization and relevance.

Memory trick: To pick and choose your logs precisely, use 'Diagnostic Settings' for granular control.

More Mitigate threats using Microsoft Sentinel questions