2: Data Connectors Flashcards

(13 cards)

1
Q

What is a data connector in Microsoft Sentinel?

A

A data connector is a way to bring external log data into Sentinel for analysis, detection, and visualization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What kinds of sources can Sentinel connect to?

A

Microsoft services like Defender, Azure AD, and Office 365, plus non-Microsoft tools like AWS, Syslog, CEF, and custom sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Where do you go to configure a data connector in Sentinel?

A

Microsoft Sentinel > [Workspace] > Configuration > Data connectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the Content Hub in Sentinel?

A

It’s where you can discover and install solution packages—bundles of connectors, rules, workbooks, and more.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What’s inside a connector’s solution bundle?

A

Prebuilt analytics rules, workbooks, hunting queries, and parsers designed for that log source.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the benefit of a connector solution bundle?

A

It gives you detection logic, dashboards, and queries tuned to that tool—no need to build content from scratch.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What happens if there’s no connector bundle for your tool?

A

You’ll need to identify log types, write your own queries, build dashboards, and handle parsing manually.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can you ingest data even if there’s no connector bundle?

A

Yes, using Syslog, Common Event Format (CEF), Azure Monitor Agent (AMA), or custom ingestion methods.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What makes connector bundles helpful for analysts?

A

They give you curated content that helps you start detecting and investigating right away—no guesswork.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do parser functions in connector bundles help?

A

They normalize and structure logs so that queries and visualizations are accurate and consistent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the difference between a connector with a bundle vs. one without?

A

With a bundle, you get ready-made content. Without one, you must build detections, queries, and visuals yourself.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Can I edit the analytics rules or workbooks included in a bundle?

A

Yes, they are fully customizable after installation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why should I care about connector bundles as a customer?

A

They save you time, reduce configuration complexity, and give you immediate security value out of the box.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly