A large enterprise is transitioning its legacy on-premises applications to a hybrid cloud architecture, incorporating both Azure and AWS. The cybersecurity architect needs to implement a comprehensive logging and monitoring strategy that consolidates security events from both cloud providers and on-premises systems, enriches alerts with threat intelligence, and enables automated responses to common incidents. The solution must support advanced analytics for threat hunting and compliance reporting. Which technical strategy is MOST suitable for these requirements?
- AEstablishing a centralized logging service with a custom-developed analytics engine for cross-platform correlation.
- BUtilizing a Security Orchestration, Automation, and Response (SOAR) platform integrated with existing on-premises log aggregation.
- CImplementing a unified, cloud-native Extended Detection and Response (XDR) platform with custom connectors for on-premises logs.
- DDeploying separate, native Security Information and Event Management (SIEM) solutions for Azure and AWS, combined with an on-premises SIEM.
Show answer & explanationAnswer & explanation
Correct answer: C. Implementing a unified, cloud-native Extended Detection and Response (XDR) platform with custom connectors for on-premises logs.
A unified, cloud-native XDR platform is ideal for a hybrid/multi-cloud environment because it provides centralized detection and response across diverse sources (endpoints, cloud, network), leverages advanced analytics and threat intelligence, and automates responses. Custom connectors can bring in on-premises logs for a truly consolidated view.
Why the other options are wrong
- A. A custom-developed analytics engine for cross-platform correlation is complex, costly to maintain, and lacks the pre-built integrations, threat intelligence, and automated response capabilities of commercial XDR solutions.
- B. While SOAR provides automation, it typically acts upon alerts from SIEM/EDR, it's not primarily a log consolidation and advanced detection platform itself, nor does it inherently provide the broad detection capabilities of XDR.
- D. Deploying separate SIEMs creates silos, complicates cross-platform correlation, and hinders unified threat hunting and automated response across the hybrid environment.
Unified Cloud-Native XDR
Unified Cloud-Native Extended Detection and Response (XDR) provides a consolidated, cloud-based platform for detecting and responding to threats across hybrid and multi-cloud environments, integrating data from various security layers.
- Correlates data across endpoints, cloud, network, identity.
- Leverages AI/ML for advanced threat detection.
- Automates and orchestrates response actions.
Memory trick: XDR is the 'Hybrid Cloud Detective' connecting all 'Security Clues'.