Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudEasy
A security operations team uses Microsoft Defender for Cloud and Azure Sentinel for their security monitoring and incident response. They want to ensure that all security alerts generated by Defender for Cloud are automatically ingested into Azure Sentinel for centralized analysis and automated playbooks. Which feature in Microsoft Defender for Cloud should be configured to achieve this integration?
- AContinuous export
- BAlert suppression rules
- CSecurity recommendations export
- DWorkflow automation
Show answer & explanationAnswer & explanation
Correct answer: A. Continuous export
Continuous export in Microsoft Defender for Cloud allows for the streaming of security alerts and recommendations to various destinations, including Azure Sentinel, for further analysis and automation.
Why the other options are wrong
- B. Alert suppression rules are used to hide unwanted alerts, not to forward them to another service.
- C. Security recommendations export is for recommendations, not security alerts, and may not be continuous.
- D. Workflow automation triggers actions based on alerts but doesn't inherently forward all alerts to Sentinel without continuous export.
Continuous Export (Defender for Cloud)
Continuous export is a Microsoft Defender for Cloud feature that allows you to stream security alerts and recommendations to Log Analytics workspaces, Azure Event Hubs, or Azure Sentinel for centralized monitoring, analysis, and automation.
- Exports security alerts and recommendations.
- Supports Log Analytics, Event Hubs, and Azure Sentinel as destinations.
- Enables integration with SIEM/SOAR solutions for advanced analysis.
Memory trick: Continuously flow the alerts, like a river to the SIEM lake.