Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

An organization wants to implement a solution to monitor and analyze security telemetry from their Azure environment, including virtual machines, storage accounts, and network activity. They need to detect advanced threats and anomalies using machine learning and behavioral analytics. Which Azure service is specifically designed for this purpose?

  1. AAzure Security Center
  2. BAzure Sphere
  3. CAzure Sentinel
  4. DAzure Monitor
Show answer & explanation

Correct answer: C. Azure Sentinel

Azure Sentinel is a cloud-native SIEM solution that uses AI and machine learning to analyze security data, detect threats, and provide intelligent analytics across an enterprise, including Azure resources.

Why the other options are wrong

  • A. Azure Security Center (now part of Microsoft Defender for Cloud) provides security posture management and threat protection, but Azure Sentinel is the dedicated SIEM for advanced analytics.
  • B. Azure Sphere is a secured application platform for internet-connected microcontroller units (MCUs) and edge devices.
  • D. Azure Monitor collects and analyzes telemetry from Azure and on-premises environments for operational insights, not primarily for security threat detection and analytics.

Azure Sentinel

Microsoft's cloud-native SIEM solution that provides intelligent security analytics and threat intelligence across the enterprise. It collects data, detects threats, investigates alerts, and responds to incidents.

  • Cloud-native SIEM and SOAR.
  • Uses AI and machine learning for threat detection.
  • Centralized security monitoring for Azure and beyond.

Memory trick: Sentinel watches Azure with intelligence.

More Describe the capabilities of Microsoft Security solutions questions