A DevOps team is implementing a security monitoring strategy for their Azure environment. They need to centralize security alerts, incidents, and audit logs from various Azure services (e.g., Azure AD, Azure Firewall, Azure Key Vault) for threat detection, investigation, and automated response. Which Azure service is designed for this purpose?
- AAzure Sentinel (now Microsoft Sentinel)
- BAzure Monitor Log Analytics
- CAzure Security Center (now Defender for Cloud)
- DAzure Network Watcher
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Sentinel (now Microsoft Sentinel)
Azure Sentinel (now Microsoft Sentinel) is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It centralizes security data from various sources, uses AI for threat detection, and provides tools for incident investigation and automated responses, directly addressing the need for centralized security monitoring, threat detection, and automated response.
Why the other options are wrong
- B. Azure Monitor Log Analytics is a service for collecting and querying log data, which can be a component of a SIEM, but it doesn't provide the full SIEM/SOAR capabilities like threat detection rules, incident management, and automated responses out-of-the-box.
- C. Azure Security Center (Defender for Cloud) focuses on cloud security posture management (CSPM) and cloud workload protection (CWP), providing recommendations and some threat protection. While it integrates with Sentinel, Sentinel is the dedicated SIEM/SOAR for centralized security operations.
- D. Azure Network Watcher provides tools for monitoring, diagnosing, and viewing metrics and logs for Azure network resources, but it's not a SIEM/SOAR solution.
Microsoft Sentinel (SIEM/SOAR)
A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that collects, detects, investigates, and responds to security threats across an enterprise.
- Centralizes security data from diverse sources.
- Uses AI and machine learning for threat detection.
- Provides incident management and automated response capabilities (SOAR).
Memory trick: Sentinel 'Watches All', 'Connects All', and 'Acts on All' security events.