Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard

An e-commerce company is experiencing a significant increase in malicious login attempts and potential data exfiltration from their Azure Blob Storage accounts. They need a service that can provide real-time threat detection, anomaly behavior analysis, and automated responses across their cloud and on-premises resources. Which Azure service should they implement?

  1. AMicrosoft Sentinel
  2. BAzure Monitor
  3. CAzure Security Center (Defender for Cloud)
  4. DAzure Firewall
Show answer & explanation

Correct answer: A. Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It provides intelligent security analytics and threat intelligence across the enterprise, including real-time threat detection, anomaly behavior analysis, and automated responses for both cloud and on-premises resources, making it ideal for detecting malicious login attempts and data exfiltration.

Why the other options are wrong

  • B. Azure Monitor collects and analyzes telemetry data for performance and availability, not primarily for security analytics and threat detection.
  • C. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection for specific resources, but Sentinel offers broader SIEM/SOAR capabilities for comprehensive enterprise-wide threat detection and response.
  • D. Azure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources, but does not provide SIEM/SOAR capabilities.

Microsoft Sentinel (SIEM/SOAR)

A scalable, cloud-native SIEM and SOAR solution that provides intelligent security analytics and threat intelligence across your enterprise.

  • Collects security data from diverse sources (cloud, on-prem).
  • Uses AI and machine learning for advanced threat detection and anomaly analysis.
  • Enables automated responses to security incidents (SOAR).

Memory trick: Sentinel: See Everything, Investigate, Execute, Learn.

More Describe Azure management and governance questions