The treasurer's Microsoft Entra ID account shows a sign-in from an unfamiliar country. Which cloud sourcetype should the analyst pull first?
Select an answer to reveal the explanation.
Short Explanation
Account takeover is an identity story, so start with the IdP's sign-in log—Entra, not the city's leftover AWS flow logs. VPC flow will not tell who typed the treasurer's password. Wrong sourcetype, wrong investigation.
Full Explanation
Cloud identity investigations require the identity provider's sourcetype. For a treasurer account-takeover on Entra ID, that is Azure AD or Entra sign-in and audit activity, which SSE and ES identity content expect. VPC Flow Logs, unrelated CloudTrail object events, and GuardDuty findings from an unused AWS account do not record the Entra authentication. Match the civic question to the typical cloud identity sourcetype.