Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard

A large pharmaceutical company is undergoing a digital transformation, moving many on-premises applications to a multi-cloud environment. The cybersecurity architect needs to establish a unified threat intelligence and incident response strategy that spans both on-premises and cloud infrastructures to meet regulatory requirements for incident reporting. Which strategy is most effective?

  1. AImplementing separate SIEM and SOAR solutions for each cloud provider and for the on-premises environment.
  2. BDeploying a cloud-native SIEM/SOAR platform with extensive integration capabilities for both on-premises logs and multi-cloud environments, enabling centralized visibility and automated response.
  3. CRelying on individual cloud provider's native security services for incident response within their respective environments.
  4. DDeveloping a manual incident response plan that requires human correlation of alerts from disparate systems.
Show answer & explanation

Correct answer: B. Deploying a cloud-native SIEM/SOAR platform with extensive integration capabilities for both on-premises logs and multi-cloud environments, enabling centralized visibility and automated response.

A centralized SIEM/SOAR platform with extensive integration capabilities provides unified visibility across hybrid and multi-cloud environments, enabling correlation of threats, automated incident response, and streamlined reporting essential for regulatory compliance.

Why the other options are wrong

  • A. Separate SIEM/SOAR solutions create silos, hindering unified threat intelligence, correlation across environments, and efficient incident response, leading to compliance gaps.
  • C. Native cloud services are often siloed to their specific cloud and do not provide unified visibility or coordinated response across a multi-cloud or hybrid environment.
  • D. Manual correlation of alerts is inefficient, prone to error, and impractical for the volume and complexity of threats in a large, hybrid environment, making timely incident reporting difficult.

Hybrid/Multi-Cloud SIEM/SOAR

A security operations platform designed to collect, analyze, and automate responses to security events across diverse environments, including on-premises, private cloud, and multiple public cloud providers.

  • Provides unified visibility and threat correlation across disparate infrastructures.
  • Enables consistent incident response workflows regardless of event source.
  • Crucial for compliance in complex IT landscapes.

Memory trick: Centralized SIEM/SOAR Unifies Hybrid Cloud Defense

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions