Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium
A security operations team wants to integrate Microsoft Defender for Cloud alerts with their existing Security Information and Event Management (SIEM) system, which is a third-party solution. The team requires a near real-time, continuous stream of all security alerts, recommendations, and secure score changes from Defender for Cloud to be exported to a custom endpoint. Which Defender for Cloud feature allows them to configure this integration?
- AWorkflow automation
- BAzure Activity Log integration
- CContinuous export
- DAzure Monitor Workbooks
Show answer & explanationAnswer & explanation
Correct answer: C. Continuous export
Continuous export in Microsoft Defender for Cloud is specifically designed to stream security alerts, recommendations, and secure score changes to various destinations, including Log Analytics workspaces, Azure Event Hubs, or specific storage accounts, in near real-time. This is the ideal mechanism for integrating with a third-party SIEM.
Why the other options are wrong
- A. Workflow automation triggers actions based on specific alerts, but doesn't provide a continuous stream of all security data.
- B. Azure Activity Log contains operational events, but not the detailed security alerts and recommendations from Defender for Cloud.
- D. Azure Monitor Workbooks are for visualization and reporting within Azure Monitor, not for exporting data to external SIEMs.
Defender for Cloud Continuous Export
A feature in Microsoft Defender for Cloud that enables streaming of security alerts, recommendations, and secure score changes to external destinations like Azure Event Hubs, Log Analytics workspaces, or Azure Storage accounts for integration with SIEMs or other monitoring tools.
- Provides near real-time data streaming.
- Supports various data types (alerts, recommendations, secure score).
- Essential for SIEM integration and long-term data retention.
Memory trick: Continuous Export: The data pipeline to your SIEM.