The canal SOC will respond from Microsoft Sentinel rather than living in the Microsoft Defender for Cloud alerts blade. What should the Azure security engineer configure?
Select an answer to reveal the explanation.
Short Explanation
If the SOC lives in Sentinel, don’t strand the alerts in the Defender for Cloud blade. Pipe those Defender for Cloud alerts into Sentinel—connector or continuous export—so response happens where the analysts actually sit.
Full Explanation
When security operations are centered on Microsoft Sentinel, Defender for Cloud alerts must be connected or continuously exported into Sentinel so incidents and response workflows can run there. Disabling alerts, substituting Defender for Cloud Apps, or removing Defender plans removes visibility instead of routing it. This alert-destination choice sets up later Domain 4 Sentinel connector work.