Data Connectors with Automation Support in Azure Sentinel PowerShell Module | SC-200 Exam

Data Connectors with Automation Support in Azure Sentinel PowerShell Module

Question

Which of the following data connectors have automation support in the Azure Sentinel PowerShell Module, Az.SecurityInsights?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D. E.

Correct Answers: C, D and E

All supported data connectors are:

Reference:

The Azure Sentinel PowerShell Module, Az.SecurityInsights, provides automation support for ingesting data from various sources into Azure Sentinel. The data connectors with automation support in this module include:

D. Office 365: This connector is used to collect audit and activity logs from Office 365 services such as Exchange, SharePoint, and OneDrive.

E. Azure Active Directory: This connector is used to collect audit and sign-in logs from Azure Active Directory.

In addition to the above, the Azure Sentinel PowerShell Module also provides automation support for several other data connectors, including:

A. Dynamics 365: This connector is used to collect audit and activity logs from Dynamics 365.

B. Cisco ASA: This connector is used to collect logs from Cisco ASA firewalls.

C. AWS CloudTrail: This connector is used to collect logs from AWS CloudTrail.

By using the Az.SecurityInsights module, organizations can automate the process of ingesting data from these sources, which can help improve the efficiency and accuracy of their security operations. The module provides PowerShell cmdlets that can be used to configure, manage, and test data connectors, as well as to perform other tasks such as creating workbooks and managing incidents in Azure Sentinel.