Microsoft Administering Windows Server AZ-802 Question # 14 Topic 2 Discussion
AZ-802 Exam Topic 2 Question 14 Discussion:
Question #: 14
Topic #: 2
You are planning the deployment of Microsoft Sentinel. Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
Microsoft Defender for Identity is the Microsoft Sentinel data connector purpose-built to monitor on-premises Active Directory domain controllers and surface exactly the insecure-protocol activity described in the requirement, including authentication attempts and sign-ins that rely on legacy or unsigned protocols such as NTLMv1, SMBv1, and unsigned LDAP binds. It does this by analyzing domain controller network traffic and Windows Events directly on the DCs, which is exactly where this insecure-protocol usage originates. The Threat Intelligence - TAXII connector ingests external threat-intelligence indicator feeds (IP addresses, file hashes, domains) from TAXII-compliant sources and has nothing to do with monitoring authentication protocol usage on domain controllers. The Azure Active Directory (Microsoft Entra ID) connector reports on cloud sign-in and audit log events for the Entra tenant, not on legacy protocol usage against on-premises AD DS domain controllers. Microsoft Defender for Cloud focuses on cloud resource security posture management and workload protection rather than detecting legacy authentication protocol usage against on-premises domain controllers. Therefore, connecting Microsoft Defender for Identity to Microsoft Sentinel is the correct connector to identify connections to the domain controllers that use insecure protocols.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit