Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard
A security architect is designing a monitoring solution for a highly sensitive application running on Azure Kubernetes Service (AKS). They need to ensure that all security events, container logs, and network flow data from the AKS cluster are collected and sent to a central security information and event management (SIEM) solution, which is Azure Sentinel. What is the most comprehensive and recommended approach to achieve this data collection?
- AEnable Container Insights for AKS and configure its data export to Sentinel.
- BManually configure diagnostic settings for the AKS cluster and all its components to send logs to a Log Analytics workspace, then connect the workspace to Sentinel.
- CDeploy the Azure Monitor Agent (AMA) to each AKS node and configure data collection rules.
- DUse the Azure Sentinel connector for Azure Kubernetes Service to ingest all relevant data.
Show answer & explanationAnswer & explanation
Correct answer: D. Use the Azure Sentinel connector for Azure Kubernetes Service to ingest all relevant data.
The Azure Sentinel connector for Azure Kubernetes Service is specifically designed for comprehensive data ingestion from AKS. It typically leverages existing diagnostic settings and Container Insights to collect control plane logs, audit logs, node logs, and pod logs, consolidating the collection process and ensuring all relevant security data is sent to Sentinel.
Why the other options are wrong
- A. Container Insights primarily focuses on performance and health metrics. While it collects some logs, it may not be comprehensive enough for all security events and network flow data required for a SIEM.
- B. Manually configuring diagnostic settings for *all* AKS cluster components (control plane, nodes, pods, network) is complex and prone to missing data, making it less comprehensive and more error-prone than the dedicated connector.
- C. Deploying AMA to each node and configuring DCRs is a valid approach for VMs, but for AKS, the built-in Sentinel connector is more streamlined and comprehensive, handling various AKS-specific log sources.
Sentinel AKS Data Connector
A dedicated data connector in Azure Sentinel designed to ingest a wide range of security events, logs, and metrics from Azure Kubernetes Service (AKS) clusters.
- Simplifies comprehensive data collection from AKS.
- Includes control plane, audit, node, and container logs.
- Integrates seamlessly with Log Analytics and Sentinel analytics.
Memory trick: AKS Connector is the Sentinel's Best Friend.