問題文
An investigation must combine Azure resource activity, Microsoft 365 administrative actions, and sign-in events. Which approach makes this practical?
選択肢
- Collect each of these sources into the workspace with the appropriate connectors, so they can be correlated in one place, and confirm the retention covers the investigation window
- Rely on Security Copilot to reach all sources without any collection
- Export all three sources to storage accounts and analyze them offline with external tools, so the workspace cost stays low and the raw records are preserved
- Query each source in its own portal, note the timestamps of the relevant events, and reconcile the results by hand into a single timeline for the investigation, confirming that each source still holds the events for that window