Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard
An e-commerce company is experiencing a significant increase in malicious login attempts and potential data breaches. They need a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution to collect security data from various Azure services and on-premises resources, analyze threats, and automate responses. Which Azure service should they implement?
- AMicrosoft Sentinel
- BAzure DDoS Protection
- CAzure Security Center (now Defender for Cloud)
- DAzure Monitor
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Sentinel
Microsoft Sentinel is Azure's cloud-native SIEM and SOAR solution. It provides capabilities for collecting security data from diverse sources, intelligent threat detection, threat investigation, and automated responses to security incidents, directly addressing the company's need for a comprehensive security operations platform.
Why the other options are wrong
- B. Azure DDoS Protection safeguards applications from Distributed Denial of Service attacks but is not a SIEM/SOAR solution.
- C. Azure Security Center (now Defender for Cloud) provides cloud security posture management (CSPM) and cloud workload protection (CWP) but is not a full-fledged SIEM/SOAR solution.
- D. Azure Monitor collects and analyzes telemetry data for operational health, not specifically for SIEM/SOAR capabilities.
Microsoft Sentinel (SIEM/SOAR)
A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.
- Collects security data from various sources.
- Uses AI and machine learning for threat detection.
- Enables automated responses to security incidents (SOAR).
Memory trick: Sentinel watches, detects, and acts on threats.