Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium

A global enterprise is expanding its cloud footprint, utilizing multiple cloud providers (Azure, AWS, GCP) and numerous SaaS applications. The cybersecurity architect needs to implement a security operations strategy that provides unified visibility, threat detection, and automated response capabilities across this complex multi-cloud and SaaS environment. Traditional on-premises SIEM/SOAR solutions are proving inadequate. Which strategy should the architect prioritize?

  1. ADeploying a cloud-native Extended Detection and Response (XDR) solution.
  2. BEnhancing existing on-premises SIEM with cloud connectors.
  3. CImplementing separate, native security services for each cloud provider.
  4. DFocusing on security awareness training for all cloud users.
Show answer & explanation

Correct answer: A. Deploying a cloud-native Extended Detection and Response (XDR) solution.

A cloud-native XDR solution is designed to provide unified visibility, threat detection, and automated response across diverse environments, including multi-cloud, SaaS, endpoints, and identities. This consolidates security data and streamlines operations far more effectively than disparate native services or extended on-premises SIEMs.

Why the other options are wrong

  • B. While cloud connectors can enhance an on-premises SIEM, they often struggle with the scale, dynamism, and specific telemetry of cloud-native services across multiple providers and SaaS applications, leading to alert fatigue and blind spots.
  • C. Using separate native services for each cloud provider creates siloed visibility and complicates unified threat detection and response across the entire multi-cloud estate.
  • D. Security awareness training is foundational but does not provide the technical capabilities for unified threat detection and automated response across a multi-cloud/SaaS environment.

Cloud-Native XDR

Cloud-native XDR (Extended Detection and Response) unifies security data from multiple domains (endpoint, cloud, identity, network) into a single platform for improved threat detection, investigation, and automated response across hybrid and multi-cloud environments.

  • Unifies telemetry across multiple security layers.
  • Provides enhanced threat detection and context.
  • Automates response actions across the attack chain.

Memory trick: Multi-cloud needs a unified eye, XDR sees all, acts fast.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions