Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A global conglomerate uses a hybrid cloud environment, including Azure, AWS, and on-premises servers. They need a unified security information and event management (SIEM) solution that can ingest security logs from all these sources, perform threat detection, and automate incident response. Which Microsoft security solution is best suited for this requirement?

  1. AMicrosoft Defender for Cloud
  2. BAzure Active Directory Identity Protection
  3. CMicrosoft Intune
  4. DMicrosoft Sentinel
Show answer & explanation

Correct answer: D. Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It's designed to collect security data from various sources across hybrid and multi-cloud environments, detect threats, and automate responses.

Why the other options are wrong

  • A. Microsoft Defender for Cloud focuses on cloud security posture management and workload protection within Azure and hybrid environments, not full SIEM capabilities across multiple clouds.
  • B. Azure Active Directory Identity Protection focuses specifically on identity-related risks and vulnerabilities within Azure AD.
  • C. Microsoft Intune is primarily for endpoint management and mobile device management, not SIEM.

Microsoft Sentinel

A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution from Microsoft.

  • Collects security data from various sources (on-prem, multi-cloud)
  • Uses AI and machine learning for threat detection
  • Enables automated incident response with playbooks

Memory trick: Sentinel watches everything, everywhere.

More Describe the capabilities of Microsoft Security solutions questions