WS1 という名前の Microsoft Sentinel ワークスペースを含む Azure サブスクリプションがあります。WS1 には、Azure アクティビティ コネクタと Microsoft Entra ID コネクタが構成されています。 どのアカウントに最も多くのアラートが発生しているか、そして各アラートに対応するインシデント情報を調査する必要があります。ソリューションは管理作業を最小限に抑える必要があります。WS1で最初に行うべきことは何でしょうか?
正解:B
To investigate which accounts generate the most alerts and correlate them with incident data, Microsoft Sentinel requires a solution package that provides identity-focused analytics and workbooks. The Cloud Identity Threat Protection Essentials solution from the Microsoft Sentinel Content hub delivers: * Prebuilt workbooks and analytics rules integrating Azure Activity, Entra ID logs, and Defender XDR alerts. * Visualizations showing users with most alerts and related incidents. * UEBA integration is optional, but installing this solution automatically provides identity-centric detection with minimal configuration. UEBA (User and Entity Behavior Analytics), by itself, detects anomalies but does not provide built-in alert correlation dashboards. Therefore, to meet the requirement with minimal administrative effort, installing the prebuilt Sentinel content package is the correct step. # Correct answer: B. From Content hub, install Cloud Identity Threat Protection Essentials