SC-100 Design security operations, identity, and compliance capabilities • Set 13
SC-100 Design security operations, identity, and compliance capabilities Practice Test 13 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Sentinel with the Microsoft 365 Defender connector. You need to create an analytics rule that generates an incident when a user is reported as compromised by Microsoft Defender for Identity. The rule should use the most efficient method to get this data. What should you use as the data source?