Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsEasy

A company is implementing a new security strategy and needs a solution to provide centralized security information and event management (SIEM) across all their Azure resources and on-premises infrastructure. This solution must offer advanced threat detection, intelligent analytics, and automated responses. Which Microsoft security solution should they choose?

  1. AMicrosoft 365 Defender
  2. BAzure Active Directory
  3. CMicrosoft Intune
  4. DMicrosoft Sentinel
Show answer & explanation

Correct answer: D. Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM solution designed for intelligent security analytics and threat intelligence across an enterprise. It collects data from various sources, detects threats, investigates alerts, and responds to incidents.

Why the other options are wrong

  • A. Microsoft 365 Defender is an XDR solution focused on protecting Microsoft 365 environments, not a general SIEM for all infrastructure.
  • B. Azure Active Directory is an identity and access management service, not a SIEM solution.
  • C. Microsoft Intune focuses on endpoint management and mobile device management, not SIEM.

Microsoft Sentinel

A scalable, cloud-native, security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution.

  • Collects security data from diverse sources.
  • Uses AI and machine learning for threat detection.
  • Provides automated response capabilities.

Memory trick: Sentinels watch the secure cloud, analyzing all events.

More Describe the capabilities of Microsoft Security solutions questions