Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium
A security architect is designing a monitoring solution for a highly sensitive application hosted on Azure Kubernetes Service (AKS). They need to collect detailed security-related audit logs from the AKS control plane and worker nodes, specifically focusing on API server access and container runtime events, and send them to Microsoft Sentinel for analysis. Which data connector should be configured in Sentinel for this purpose?
- ACommon Event Format (CEF) connector
- BAzure Activity Log connector
- CAzure Diagnostics connector
- DAzure Kubernetes Service (AKS) connector
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Kubernetes Service (AKS) connector
The Azure Kubernetes Service (AKS) data connector in Microsoft Sentinel is specifically designed to ingest AKS audit logs and other security-related data from both the control plane and worker nodes, providing comprehensive visibility for AKS environments.
Why the other options are wrong
- A. CEF is for ingesting logs from external security devices or applications, not native Azure services like AKS.
- B. Azure Activity Log captures Azure resource management operations, not granular AKS control plane or container runtime logs.
- C. Azure Diagnostics collects various logs and metrics from resources, but the dedicated AKS connector offers a more tailored and comprehensive solution for AKS security data.
Microsoft Sentinel AKS Connector
The Microsoft Sentinel Azure Kubernetes Service (AKS) data connector enables the ingestion of detailed AKS audit logs, control plane logs, and other security data into Sentinel for comprehensive threat detection and analysis.
- Collects audit logs from AKS control plane.
- Gathers security events from worker nodes.
- Provides deep visibility into containerized environments.
Memory trick: Each service has its own 'plug' for Sentinel.