Microsoft Security, Compliance, and Identity Fundamentals — Question 135
You have an Azure subscription that contains a Log Analytics workspace.
You need to onboard Microsoft Sentinel.
What should you do first?
Answer options
- A. Create a hunting query.
- B. Correlate alerts into incidents.
- C. Connect to your security sources.
- D. Create a custom detection rule.
Correct answer: C
Explanation
The first step in onboarding Microsoft Sentinel is to connect to your security sources, as this allows Sentinel to gather the necessary data for threat detection and response. The other options, such as creating queries or rules, are actions that can be performed after the security sources are connected and are not the initial step in the onboarding process.