MS-900 · Question #402
A company plans to implement Microsoft Sentinel. You need to describe the capabilities of Microsoft Sentinel. Which two sets of capabilities does it provide? Each correct answer presents a complete…
The correct answer is A. security orchestration, automation, and response D. security information and event management. Microsoft Sentinel is a cloud-native SIEM and SOAR solution that combines security event management with automated response capabilities. Understanding its core feature set is essential for the SC-900 and related Microsoft security certifications.
Question
Options
- Asecurity orchestration, automation, and response
- Bnumeric score to measure an organization's security posture
- Csecurity and management of devices, data, and users for managed service providers
- Dsecurity information and event management
How the community answered
(49 responses)- A80% (39)
- B6% (3)
- C14% (7)
Why each option
Microsoft Sentinel is a cloud-native SIEM and SOAR solution that combines security event management with automated response capabilities. Understanding its core feature set is essential for the SC-900 and related Microsoft security certifications.
Microsoft Sentinel provides Security Orchestration, Automation, and Response (SOAR) capabilities through automation rules and playbooks powered by Azure Logic Apps, allowing security teams to automatically respond to and remediate threats without manual intervention.
A numeric score to measure an organization's security posture describes Microsoft Secure Score, a feature within Microsoft Defender for Cloud and Microsoft 365 Defender, not Microsoft Sentinel.
Security and management of devices, data, and users for managed service providers describes Microsoft 365 Lighthouse, a tool designed specifically for MSPs to manage multiple customer tenants, which is unrelated to Sentinel's capabilities.
Microsoft Sentinel is fundamentally a Security Information and Event Management (SIEM) solution, collecting and analyzing log data from across an organization's environment to detect threats, generate alerts, and provide threat visibility at cloud scale.
Concept tested: Microsoft Sentinel SIEM and SOAR core capabilities
Source: https://learn.microsoft.com/en-us/azure/sentinel/overview
Topics
Community Discussion
No community discussion yet for this question.