Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingHard

A security team needs a centralized solution to collect, store, and correlate security logs and events from various sources across their Azure environment and on-premises infrastructure. They also require advanced threat detection, investigation, and automated response capabilities. Which Azure service is designed for this purpose?

  1. AAzure Log Analytics
  2. BAzure Sentinel
  3. CAzure Monitor
  4. DAzure Security Center
Show answer & explanation

Correct answer: B. Azure Sentinel

Azure Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It provides intelligent security analytics and threat intelligence across the enterprise, enabling collection, detection, investigation, and automated response to security threats.

Why the other options are wrong

  • A. Azure Log Analytics is a service used by Azure Monitor and Sentinel for querying and analyzing logs, but it's not the full SIEM solution itself.
  • C. Azure Monitor collects and analyzes telemetry but is a general-purpose monitoring service, not a dedicated SIEM/SOAR.
  • D. Azure Security Center provides security posture management and threat protection for Azure resources, but Azure Sentinel is the full SIEM/SOAR.

Azure Sentinel

A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.

  • Collects security data across all sources.
  • Uses AI and machine learning for intelligent threat detection.
  • Enables rapid investigation and automated response to threats.

Memory trick: Sentinel stands guard, collecting logs and hunting threats.

More Describe Azure identity, security, and networking questions