Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesEasy

A mid-sized financial institution is undergoing a digital transformation, migrating many on-premises applications and data to a hybrid cloud environment. The security team is facing challenges in gaining unified visibility into security events, managing alerts, and automating responses across both environments. The current setup involves separate security tools for on-premises and cloud, leading to blind spots and delayed incident response. Which approach would best address these challenges by providing a centralized view and automated security operations?

  1. AImplementing a dedicated Cloud Security Posture Management (CSPM) solution for cloud assets.
  2. BEnhancing Data Loss Prevention (DLP) policies and enforcement across all data repositories.
  3. CDeploying an advanced Intrusion Detection System/Intrusion Prevention System (IDS/IPS) at network perimeters.
  4. DAdopting a unified Hybrid/Multi-Cloud Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platform.
Show answer & explanation

Correct answer: D. Adopting a unified Hybrid/Multi-Cloud Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platform.

A unified Hybrid/Multi-Cloud SIEM/SOAR platform is designed to consolidate security event data, provide centralized visibility, and automate incident response workflows across both on-premises and diverse cloud environments. This directly addresses the challenges of fragmented visibility, alert overload, and delayed response in a hybrid cloud setup.

Why the other options are wrong

  • A. CSPM focuses on cloud configuration and compliance, not the unified event management and automated response across both on-premises and cloud environments.
  • B. DLP focuses on preventing data exfiltration but does not provide the unified event visibility and automated response capabilities across hybrid environments.
  • C. IDS/IPS are perimeter defenses that provide threat detection but do not offer the centralized event management, correlation, and automated response capabilities needed for a hybrid cloud security operations strategy.

Hybrid/Multi-Cloud SIEM/SOAR

This refers to the integration of Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) capabilities to provide unified security visibility, alert management, and automated incident response across complex hybrid and multi-cloud environments.

  • Centralizes security event data from diverse sources.
  • Automates incident detection and response workflows.
  • Provides a holistic view of security posture across hybrid/multi-cloud.
  • Reduces manual effort and improves response times.

Memory trick: See all, automate all, respond fast, hybrid or not.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions