Microsoft Security, Compliance, and Identity Fundamentals — Question 170
You have an Azure subscription that contains a Log Analytics workspace.
You need to onboard Microsoft Sentinel.
What should you do first?
Answer options
- A. Create a hunting query.
- B. Correlate alerts into incidents.
- C. Connect to your data sources.
- D. Create a custom detection rule.
Correct answer: C
Explanation
The first step to onboard Microsoft Sentinel involves connecting to your data sources, which allows Sentinel to collect and analyze data. The other options, such as creating queries or rules, are actions that can only be performed once data sources are properly connected.