Courseiva
Describe Azure management and governancemediumMultiple ChoiceObjective-mapped

AZ-900 Describe Azure management and governance Practice Question

Which Azure service provides a cloud-native SIEM (Security Information and Event Management) solution for detecting and responding to threats?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Defender for Cloud (a CSPM tool) with a SIEM, because both deal with security, but Defender for Cloud does not provide the log aggregation, event correlation, and threat hunting capabilities that define a SIEM like Microsoft Sentinel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Sentinel

Microsoft Sentinel is the correct answer because it is a cloud-native SIEM (Security Information and Event Management) solution that provides intelligent security analytics and threat intelligence across the enterprise. It collects data from various sources, including Azure, on-premises, and other clouds, and uses built-in AI and machine learning to detect and respond to threats in real time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and workload protection tool that assesses resource configurations, identifies misconfigurations, and provides compliance recommendations. It focuses on proactively hardening your cloud infrastructure rather than operating as a security information and event management (SIEM) platform. While Defender for Cloud can generate security alerts, it lacks Sentinel's ability to centrally collect and query logs from diverse sources, create custom analytics rules, and run automated incident response playbooks. Sentinel is purpose-built for security operations center workflows, making it the correct SIEM/SOAR solution.

  • Azure Monitor

    Why it's wrong here

    Azure Monitor is a general-purpose monitoring service that captures metrics, diagnostics, and application telemetry to help you ensure performance and availability of resources. Although it can store log data and even security-related entries, it is not designed for security incident detection, threat investigation, or coordinated response actions. Microsoft Sentinel is a dedicated SIEM/SOAR platform that specifically focuses on security analytics—correlating alerts, detecting suspicious activity, and orchestrating response via playbooks—whereas Azure Monitor lacks built-in threat intelligence, UEBA, and automated security remediation. Thus, Sentinel is the security analytics solution, not Azure Monitor.

  • Microsoft Sentinel

    Why this is correct

    Microsoft Sentinel is a cloud-native SIEM and SOAR platform that provides intelligent security analytics and threat response across your entire enterprise. It ingests data from various sources, including Azure services, on-premises environments, and third-party products, then uses built-in analytics and user and entity behavior analytics (UEBA) to detect and investigate threats. Sentinel also includes automation playbooks that allow you to respond to incidents automatically, reducing manual effort. This combination of security information management and automated orchestration makes Sentinel the correct choice for a comprehensive security analytics platform.

  • Azure DDoS Protection

    Why it's wrong here

    Azure DDoS Protection is a network-layer defense service specifically designed to mitigate volumetric distributed denial-of-service attacks, such as SYN floods and UDP amplification attacks. It does not ingest security logs, detect a wide range of threats, or provide incident response automation across an enterprise environment. Microsoft Sentinel, in contrast, is a comprehensive security analytics platform that collects data from multiple sources, correlates events, and enables automated threat response. DDoS Protection only addresses availability attacks, not the broader threat detection and orchestration capabilities of a SIEM.

About these practice questions

Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.