AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your company has multiple Azure subscriptions. You need to centralize security alerts and incidents in a single dashboard for the security operations center (SOC) team. The solution should provide advanced analytics and threat detection. Which service should you use?
⚠ Common exam trap
It's easy for candidates to confuse Microsoft Defender for Cloud (a CSPM and workload protection tool) with a SIEM solution, but Defender for Cloud lacks the centralized incident management and advanced analytics capabilities that Microsoft Sentinel provides for a SOC dashboard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that centralizes security alerts and incidents from multiple Azure subscriptions into a single dashboard. It provides advanced analytics, built-in threat detection, and AI-driven investigation capabilities, making it ideal for a SOC team requiring a unified view across the enterprise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Monitor
Why it's wrong here
Azure Monitor is a platform for collecting, analyzing, and acting on telemetry from Azure resources, applications, and on-premises infrastructure. While it provides metrics, logs, and alerting via Log Analytics workspaces, it is not a SIEM and lacks native capabilities for correlating security alerts across multiple subscriptions, managing incidents, or performing threat hunting. Azure Monitor can store security logs, but the centralized security alert management described requires a dedicated SIEM, not a general-purpose monitoring service.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a cloud-native SIEM and SOAR solution specifically designed to collect and centralize security alerts and data from all Azure subscriptions and external sources. It uses built-in analytics, fusion, and UEBA to detect threats, and provides incident management, investigation, and automated response across the enterprise. For the requirement to centralize security alerts across multiple Azure subscriptions, Sentinel is the correct choice because it aggregates alerts from Defender for Cloud and other sources into a single, actionable incident queue.
- ✗
Microsoft 365 Defender
Why it's wrong here
Microsoft 365 Defender is an integrated security suite that coordinates threat detection and response across Microsoft 365 domains, such as email (Defender for Office 365), endpoints (Defender for Endpoint), identity (Defender for Identity), and cloud apps (Defender for Cloud Apps). It is not a SIEM and does not collect or centralize Azure resource security alerts across subscriptions; its data sources are primarily Microsoft 365 and user/device telemetry. Therefore, it would not satisfy the need to consolidate Azure multi-subscription security alerts.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection (CWP) solution that provides security recommendations, regulatory compliance assessments, and workload-specific alerts for Azure resources. While it does generate security alerts, it is not a SIEM and does not provide the centralized aggregation, correlation, and advanced threat-hunting across multiple subscriptions that Sentinel offers. In fact, Defender for Cloud alerts are commonly ingested into Microsoft Sentinel as a data source, not used as the central SIEM itself.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.