Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

A company requires a solution to centralize the collection of security logs and events from various Azure resources, on-premises servers, and other cloud environments. They need to be able to analyze these logs to detect threats and respond to security incidents. Which Azure service is best suited for this requirement?

  1. AAzure Monitor
  2. BAzure Security Center
  3. CAzure Active Directory
  4. DAzure Sentinel
Show answer & explanation

Correct answer: D. Azure Sentinel

Azure Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It collects security data from various sources, detects threats, and helps respond to incidents.

Why the other options are wrong

  • A. Azure Monitor collects and analyzes telemetry from Azure resources but is not specifically a SIEM.
  • B. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection.
  • C. Azure Active Directory is an identity and access management service.

Azure Sentinel

Azure Sentinel is Microsoft's cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.

  • Centralizes security data collection
  • Uses AI for threat detection
  • Provides automated response capabilities (SOAR)
  • Integrates with various data sources

Memory trick: Sentinel is your security watchtower, collecting all clues and sounding the alarm.

More Describe Azure identity, security, and networking questions