Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard
A global enterprise is migrating its legacy applications to a multi-cloud environment (Azure and AWS) while maintaining some critical services on-premises. The security architect is tasked with implementing a unified security operations center (SOC) that can collect security logs and alerts from all these diverse environments, correlate them, and provide a single pane of glass for threat detection and response, crucial for the 'assume breach' principle. Which Microsoft security service is BEST suited to aggregate and analyze security data across this hybrid and multi-cloud landscape?
- AAzure Monitor
- BAzure Network Watcher
- CAzure Security Center (now Microsoft Defender for Cloud)
- DAzure Sentinel (now Microsoft Sentinel)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Sentinel (now Microsoft Sentinel)
The scenario describes the need for a unified SOC, log aggregation, correlation, and a single pane of glass for threat detection and response across hybrid and multi-cloud environments. Microsoft Sentinel (formerly Azure Sentinel) is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution specifically designed for this purpose.
Why the other options are wrong
- A. Azure Monitor collects monitoring data (metrics, logs) from Azure resources, but it's not a full SIEM/SOAR solution for cross-platform threat detection and response.
- B. Azure Network Watcher provides tools for monitoring, diagnosing, and viewing metrics in an Azure virtual network, not for enterprise-wide security log aggregation and analysis.
- C. Microsoft Defender for Cloud (formerly Azure Security Center) provides cloud security posture management (CSPM) and cloud workload protection (CWP) for Azure, AWS, and GCP, but it's primarily for posture and workload protection, not a full SIEM for log aggregation and correlation across all environments.
Microsoft Sentinel
A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.
- Ingests data from diverse sources (Azure, AWS, Google Cloud, on-premises, other security solutions).
- Uses AI and machine learning for threat detection.
- Enables automated response to security incidents.
Memory trick: Sentinel Sees All Security, Everywhere.