Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium
A DevOps team is implementing a security monitoring strategy for their Azure environment. They need a solution that can collect security logs from various Azure services (e.g., Azure AD, Azure Firewall, VMs), detect sophisticated threats using built-in machine learning, and provide automated incident response capabilities (SOAR). Which Azure service is designed to fulfill these comprehensive security requirements?
- AAzure Security Center (Defender for Cloud)
- BAzure Activity Log
- CMicrosoft Sentinel
- DAzure Monitor
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Sentinel
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It provides capabilities for data collection, threat detection using analytics and machine learning, threat hunting, and automated response playbooks, fulfilling all the mentioned requirements.
Why the other options are wrong
- A. Azure Security Center (now Defender for Cloud) provides security posture management and threat protection across workloads, but Sentinel is the full-fledged SIEM/SOAR solution for comprehensive log correlation and automated response.
- B. Azure Activity Log records control-plane events in Azure, but it's only one source of logs and does not provide comprehensive SIEM/SOAR capabilities.
- D. Azure Monitor collects and analyzes metrics and logs from various Azure resources, but it's a general monitoring service, not specifically a SIEM/SOAR for security.
Microsoft Sentinel (SIEM/SOAR)
A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution from Microsoft.
- Collects security data from various sources.
- Uses analytics and machine learning for threat detection.
- Enables automated incident response with playbooks (SOAR).
Memory trick: Sentinel: The Guard Dog for your Azure, Seeing and Responding to Threats!