Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard
A global company needs to monitor its Azure environment for security threats, collect security events from various sources (Azure, on-premises, and other clouds), and automate responses to common security incidents. They are looking for a unified security operations platform. Which Azure service is designed for this comprehensive SIEM and SOAR functionality?
- AMicrosoft Sentinel
- BAzure Monitor
- CAzure AD Identity Protection
- DAzure Security Center (now Defender for Cloud)
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Sentinel
Microsoft Sentinel is Azure's cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It's designed to collect security data from diverse sources, detect and investigate threats, and automate responses, fulfilling the requirement for a unified security operations platform.
Why the other options are wrong
- B. Azure Monitor is for collecting and analyzing operational metrics and logs across Azure resources, not specifically for SIEM/SOAR.
- C. Azure AD Identity Protection focuses on detecting and remediating identity-based risks in Azure Active Directory, not a general SIEM/SOAR platform.
- D. Azure Security Center (now Defender for Cloud) focuses on cloud security posture management (CSPM) and cloud workload protection (CWP), offering recommendations and protections but not comprehensive SIEM/SOAR.
Microsoft Sentinel (SIEM/SOAR)
A scalable, cloud-native, security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution that delivers intelligent security analytics and threat intelligence.
- Aggregates security data from all sources.
- Utilizes AI/ML for advanced threat detection.
- Automates responses to security incidents using playbooks.
Memory trick: Sentinel guards and automates security actions.