Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium

A financial services company needs to monitor its Azure environment for security threats and abnormal behaviors across all its subscriptions and connected on-premises infrastructure. They require a centralized platform for security information and event management (SIEM) that can collect data from various sources, detect threats using AI, and automate responses. Which Azure service meets these requirements?

  1. AAzure Security Center (Defender for Cloud)
  2. BAzure Advisor
  3. CMicrosoft Sentinel
  4. DAzure Monitor
Show answer & explanation

Correct answer: C. Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It provides intelligent security analytics and threat intelligence across enterprise environments, including collecting data from diverse sources, detecting threats using machine learning, and enabling automated responses.

Why the other options are wrong

  • A. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection across hybrid and multi-cloud environments.
  • B. Azure Advisor provides personalized recommendations for optimizing Azure deployments.
  • D. Azure Monitor focuses on collecting, analyzing, and acting on telemetry data for performance and availability.

Microsoft Sentinel

A scalable, cloud-native, security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution.

  • Collects security data across your organization.
  • Detects threats using analytics and threat intelligence.
  • Investigates threats with AI and automates responses.

Memory trick: Sentinel: See, Investigate, Execute, Learn.

More Describe Azure management and governance questions