The canal authority is standing up a greenfield Microsoft Sentinel SOC. In which order should the Azure security engineer enable data ingestion?
Select an answer to reveal the explanation.
Short Explanation
Don’t hang connectors in mid-air. Spin up the Log Analytics workspace, turn on Microsoft Sentinel, then pull the Content Hub connectors—Activity, Defender for Cloud, Entra—the order that actually sticks.
Full Explanation
Microsoft Sentinel is enabled on a Log Analytics workspace. The practical enable-and-configure sequence is create the workspace, enable Sentinel, then install data connectors from Content Hub (for example Microsoft Defender for Cloud, Azure Activity, and Microsoft Entra ID). Connectors cannot meaningfully run without the workspace and Sentinel enablement, and custom parser authoring is not the first AZ-500 step for this skill.