Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium

A security operations team wants to integrate Microsoft Defender for Cloud alerts with their existing Security Information and Event Management (SIEM) system, Microsoft Sentinel, for centralized incident management and correlation. The team needs to ensure that all high-severity security alerts from Defender for Cloud are automatically streamed to Sentinel in near real-time. Which Defender for Cloud feature should be configured to achieve this integration?

  1. AContinuous export
  2. BWorkflow automation
  3. CData export to Storage Account
  4. DAzure Activity Log integration
Show answer & explanation

Correct answer: A. Continuous export

Continuous export in Microsoft Defender for Cloud allows you to stream security alerts and recommendations to Azure Monitor Log Analytics workspaces (which Sentinel uses) or Azure Event Hubs in near real-time. This is the primary method for integrating Defender for Cloud alerts with SIEMs like Sentinel.

Why the other options are wrong

  • B. Workflow automation can trigger actions based on alerts but is not the primary mechanism for streaming all alerts to a SIEM.
  • C. Exporting data to a Storage Account is typically for archival or batch processing, not near real-time SIEM integration.
  • D. Azure Activity Log integration covers control plane operations, but not the specific security alerts generated by Defender for Cloud's enhanced protections.

Defender for Cloud Continuous Export

Continuous export in Microsoft Defender for Cloud enables the automatic streaming of security alerts and recommendations to Azure Monitor Log Analytics workspaces, Azure Event Hubs, or Azure Storage for further analysis, reporting, or integration with SIEM/SOAR solutions.

  • Streams data in near real-time.
  • Supports alerts and recommendations.
  • Essential for SIEM/SOAR integration (e.g., Microsoft Sentinel).
  • Configurable at the subscription or management group level.

Memory trick: Export's ease: Alerts flow freely, into the SIEM's sea.

More Mitigate threats using Microsoft Defender for Cloud questions