AZ-900 Describe Azure management and governance Practice Question
Which Azure service provides a SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution?
⚠ Common exam trap
Candidates often confuse Microsoft Defender for Cloud (or its predecessor Azure Security Center) with a SIEM solution, but it is primarily a security posture management and workload protection tool, not a full SIEM/SOAR platform like Microsoft Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is the correct answer because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. It provides intelligent security analytics and threat intelligence across the enterprise, enabling security teams to collect data at cloud scale, detect threats, investigate incidents, and automate responses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud delivers cloud security posture management and threat protection specifically for Azure workloads, continuously assessing misconfigurations and hardening resources. However, it is not a security information and event management (SIEM) platform; it does not aggregate and correlate data from on-premises, other clouds, and non-Microsoft sources for enterprise-wide incident management. The organization needs a dedicated SIEM/SOAR solution like Microsoft Sentinel to centralize detection, investigation, and automated response across the entire environment.
- ✗
Azure Monitor
Why it's wrong here
Azure Monitor is designed for operational telemetry, collecting metrics, logs, and alerts from Azure resources to track performance, availability, and application diagnostics. While it can ingest some security-related data, it lacks the out-of-the-box security content, threat-intelligence connectors, and incident-management workflows that define a SIEM. It also does not provide SOAR capabilities such as automated playbooks to orchestrate incident response, making it unsuitable for the described security operations requirement.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is the correct choice because it is Azure's native, cloud-scale security information and event management (SIEM) and security orchestration, automated response (SOAR) service. It aggregates security data from any source—including users, applications, servers, and other clouds—and uses built-in AI and analytics to detect anomalies, while its playbooks enable automated response to threats. This directly matches the need for continuous security monitoring, threat detection, and response automation.
- ✗
Azure Security Center
Why it's wrong here
Azure Security Center, now part of Microsoft Defender for Cloud, focuses on security posture management and provides a unified view of security state across Azure resources, but it is not a SIEM/SOAR solution. It offers recommendations and alerts, yet it does not perform extensive multi-source log correlation or provide a full-featured incident management and automated response environment. Enterprise-wide security analytics and response automation are delivered by Microsoft Sentinel, making this option incorrect.
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Cloud-native
Cloud-native is a modern approach to building and running applications that fully exploits the cloud computing model by using containers, microservices, serverless functions, and automated orchestration to achieve scalability, resilience, and rapid delivery.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.