Microsoft 365 Defender データ コネクタを使用する Microsoft Sentinel ワークスペースがあります。 Microsoft Sentinel から Microsoft 365 インシデントを調査します。 Microsoft Defender for Cloud Apps によって生成されたアラートを含めるようにインシデントを更新する必要があります。 何を使えばいいのでしょうか?
正解:D
Microsoft Sentinel incidents that originate from the Microsoft 365 Defender data connector are synchronized automatically with the Microsoft 365 Defender portal. To add or link an additional alert (for example, from Defender for Cloud Apps) to an existing incident, you must do it from the Microsoft 365 Defender portal's Alerts page, not directly in Sentinel. Once updated in Microsoft 365 Defender, the changes sync back to Sentinel, maintaining incident parity between both platforms. # Correct Answer: D. the Alerts page in the Microsoft 365 Defender portal