Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium
A company requires a centralized security information and event management (SIEM) solution in Azure to collect security data from various sources, perform threat detection, and enable rapid response to security incidents. Which Azure service is designed for this purpose?
- AAzure Sentinel
- BAzure Active Directory
- CAzure Security Center
- DAzure Network Watcher
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Sentinel
Azure Sentinel is a scalable, cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that provides intelligent security analytics and threat intelligence across the enterprise.
Why the other options are wrong
- B. Azure Active Directory is an identity service, not a SIEM solution.
- C. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection, but Sentinel is the full SIEM solution.
- D. Azure Network Watcher provides tools to monitor, diagnose, and view metrics for Azure networks, not a SIEM.
Azure Sentinel
A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.
- Collects security data from various sources.
- Uses AI and machine learning for threat detection.
- Enables rapid incident response and automation.
Memory trick: Sentinel is the 'security guard' who 'watches' and 'responds' to all 'threats'.