Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard
An e-commerce company is experiencing a significant increase in malicious login attempts and potential data exfiltration from their Azure Blob Storage accounts. They need a service that can provide real-time threat detection, anomaly behavior analysis, and automated responses across their cloud and on-premises resources. Which Azure service should they implement?
- AMicrosoft Sentinel
- BAzure Monitor
- CAzure Security Center (Defender for Cloud)
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Sentinel
Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It provides intelligent security analytics and threat intelligence across the enterprise, including real-time threat detection, anomaly behavior analysis, and automated responses for both cloud and on-premises resources, making it ideal for detecting malicious login attempts and data exfiltration.
Why the other options are wrong
- B. Azure Monitor collects and analyzes telemetry data for performance and availability, not primarily for security analytics and threat detection.
- C. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection for specific resources, but Sentinel offers broader SIEM/SOAR capabilities for comprehensive enterprise-wide threat detection and response.
- D. Azure Firewall is a managed, cloud-based network security service that protects your Azure Virtual Network resources, but does not provide SIEM/SOAR capabilities.
Microsoft Sentinel (SIEM/SOAR)
A scalable, cloud-native SIEM and SOAR solution that provides intelligent security analytics and threat intelligence across your enterprise.
- Collects security data from diverse sources (cloud, on-prem).
- Uses AI and machine learning for advanced threat detection and anomaly analysis.
- Enables automated responses to security incidents (SOAR).
Memory trick: Sentinel: See Everything, Investigate, Execute, Learn.