問題文
An investigation needs both the Microsoft 365 administrative actions taken last month and correlated security signals from Azure resources. Which approach fits?
選択肢
- Query Microsoft Sentinel only, because a Sentinel workspace always contains every Microsoft 365 administrative action without any additional configuration.
- Use Defender for Cloud security alerts, which include all administrative actions.
- Query Microsoft Purview Audit for the Microsoft 365 activity, and use Microsoft Sentinel for correlation across the collected security data.
- Query Microsoft Purview Audit only, because it contains Azure resource activity as well.