フリー問題

Implementing End-to-End Security Controls for Cloud and AI Workloads (SC-500) のフリー問題 16 / 20 問目

問題文

An investigation needs both the Microsoft 365 administrative actions taken last month and correlated security signals from Azure resources. Which approach fits?

選択肢

  1. Query Microsoft Sentinel only, because a Sentinel workspace always contains every Microsoft 365 administrative action without any additional configuration.
  2. Use Defender for Cloud security alerts, which include all administrative actions.
  3. Query Microsoft Purview Audit for the Microsoft 365 activity, and use Microsoft Sentinel for correlation across the collected security data.
  4. Query Microsoft Purview Audit only, because it contains Azure resource activity as well.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。