A security architect needs to reduce mean time to detect (MTTD) for identity-based attacks across a hybrid environment. Which Microsoft Sentinel feature should be prioritized?
-
A
Enable User and Entity Behavior Analytics (UEBA) to baseline and detect anomalous identity activity
-
B
Configure scheduled analytics rules with KQL queries running every 5 minutes
-
C
Deploy Azure Monitor Alerts for all Azure AD sign-in failures
-
D
Use Microsoft Defender for Cloud Apps shadow IT discovery reports