Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard

An e-commerce company is experiencing a significant increase in malicious login attempts and potential data exfiltration from their Azure Blob Storage accounts. They need a security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution that can collect security data from across their Azure environment, detect advanced threats using AI, and automate responses to security incidents. Which Azure service should they implement?

  1. AMicrosoft Sentinel
  2. BAzure Active Directory Identity Protection
  3. CAzure Firewall
  4. DAzure Security Center
Show answer & explanation

Correct answer: A. Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM and SOAR solution that provides intelligent security analytics and threat intelligence across the enterprise. It collects security data from various sources, uses AI to detect threats, and enables automated responses to incidents.

Why the other options are wrong

  • B. Azure Active Directory Identity Protection focuses specifically on detecting identity-based risks and automating remediation for user accounts, not broad threat detection across the entire Azure environment.
  • C. Azure Firewall provides network-level threat protection and filtering for Azure Virtual Network resources, but it is a perimeter security service, not a SIEM/SOAR solution for broad threat detection and incident response.
  • D. Azure Security Center (now Microsoft Defender for Cloud) provides cloud security posture management (CSPM) and cloud workload protection (CWPP), offering security recommendations and threat protection, but it is not a full SIEM/SOAR solution for cross-enterprise threat detection and automated response.

Microsoft Sentinel

A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.

  • Cloud-native SIEM/SOAR
  • Collects security data from many sources
  • Uses AI for threat detection
  • Automates incident response

Memory trick: Sentinel: The 'sentinel' watches, detects, and acts.

More Describe Azure management and governance questions