Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard

A financial services company needs to monitor its Azure environment for security threats and respond automatically to detected incidents. They require a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that integrates with various Azure services and third-party security tools. Which Azure service should they use?

  1. AAzure Security Center
  2. BMicrosoft Sentinel
  3. CAzure Monitor
  4. DAzure Network Watcher
Show answer & explanation

Correct answer: B. Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM and SOAR solution that provides intelligent security analytics across an enterprise. It collects data from various sources, detects threats, investigates incidents, and automates responses.

Why the other options are wrong

  • A. Azure Security Center (now Microsoft Defender for Cloud) provides cloud security posture management and threat protection, but Sentinel offers full SIEM/SOAR capabilities.
  • C. Azure Monitor collects and analyzes telemetry from Azure resources, but it's not a dedicated SIEM/SOAR solution.
  • D. Azure Network Watcher provides tools for monitoring, diagnosing, and viewing metrics for network resources, not a SIEM/SOAR.

Microsoft Sentinel

Microsoft Sentinel is a scalable, cloud-native, security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution.

  • Collects data across all users, devices, applications, and infrastructure.
  • Uses AI and machine learning for threat detection.
  • Automates threat response with playbooks.

Memory trick: Sentinel Sees Security, Solves Swiftly.

More Describe Azure management and governance questions