You need to collect and automatically analyze security events from Azure Active Directory (Azure AD). Which service should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Sentinel.
Why this is the answer
Azure Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It collects security data from various sources, including Azure AD, and uses AI and machine learning to detect and analyze threats automatically, making it ideal for collecting and analyzing security events. Azure Synapse Analytics is an analytics service that brings together enterprise data warehousing and Big Data analytics, not primarily for security event analysis. Azure AD Connect synchronizes on-premises directories with Azure AD, and Azure Key Vault securely stores and manages cryptographic keys and other secrets, neither of which are designed for security event collection and analysis.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed