Microsoft 365 Defenderデータコネクタを使用するMicrosoft Sentinelワークスペースをお持ちです。 Microsoft Sentinel から、Microsoft 365 のインシデントを調査します。 Microsoft Defender for Cloud Apps によって生成されたアラートを含めるように、インシデントを更新する必要があります。 何を使うべきでしょうか?
正解:D
Microsoft Sentinel incidents that originate from the Microsoft 365 Defender data connector are synchronized automatically with the Microsoft 365 Defender portal . To add or link an additional alert (for example, from Defender for Cloud Apps) to an existing incident, you must do it from the Microsoft 365 Defender portal's Alerts page , not directly in Sentinel. Once updated in Microsoft 365 Defender, the changes sync back to Sentinel, maintaining incident parity between both platforms. # Correct Answer: D. the Alerts page in the Microsoft 365 Defender portal