A security administrator needs to detect and monitor suspicious activity across Azure workloads. Which service provides this capability?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Sentinel.
Why this is the answer
Azure Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It collects security data from various sources, detects threats using built-in analytics and machine learning, investigates incidents, and automates responses. This makes it ideal for monitoring and detecting suspicious activity across Azure workloads. Azure Advisor provides recommendations for optimizing Azure resources, not security monitoring. Azure App Insights is an Application Performance Management (APM) service for monitoring application performance and usage. Azure Policy helps enforce organizational standards and assess compliance, but it doesn't actively monitor for suspicious security events.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed