Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A security operations center (SOC) team needs a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution to collect security data from various sources, detect threats using AI, and automate incident response workflows. Which Azure security service meets these requirements?

  1. AAzure Active Directory Identity Protection
  2. BAzure Security Center
  3. CMicrosoft Sentinel
  4. DAzure Firewall
Show answer & explanation

Correct answer: C. Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM and SOAR solution that provides scalable data collection, intelligent threat detection using analytics and AI, threat hunting capabilities, and automated response playbooks.

Why the other options are wrong

  • A. Azure Active Directory Identity Protection focuses on detecting and remediating identity-based risks, not comprehensive SIEM/SOAR.
  • B. Azure Security Center (now part of Microsoft Defender for Cloud) focuses on cloud security posture management and workload protection, not SIEM/SOAR.
  • D. Azure Firewall is a network security service for filtering traffic, not for event management or incident response automation.

Microsoft Sentinel

A scalable, cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.

  • Collects security data from diverse sources.
  • Uses AI for threat detection.
  • Automates incident response with playbooks.

Memory trick: Sentinel: See Everything, Investigate, Execute, Learn.

More Describe the capabilities of Microsoft Security solutions questions