A security operations center must triage incidents across Microsoft 365 Defender and Microsoft Sentinel simultaneously. What is the recommended integration approach to avoid duplicate incident management?
-
A
Enable the Microsoft Defender XDR connector in Sentinel with incident sync to manage incidents in a single pane
-
B
Create separate response procedures for each portal and reconcile weekly
-
C
Use Microsoft Sentinel as the primary SIEM and manually close Defender XDR alerts after handling
-
D
Configure Logic Apps to merge incidents from both portals into a ServiceNow ticket