A security operations centre is evaluating Microsoft Sentinel as a cloud-native SIEM and SOAR platform. Which TWO capabilities does Microsoft Sentinel provide? Select TWO.
- ACollecting and correlating security data at scale across users, devices, apps, and infrastructure. Correct
- BStoring application secrets, encryption keys, and certificates with managed access control.
- CContinuously scoring Azure resource configurations against built-in security standards.
- DAutomating incident response through playbooks that orchestrate actions across connected systems. Correct
- EBrokering portal-based RDP and SSH sessions to virtual machines without public IPs.
Why A is correct: Sentinel ingests and correlates data at cloud scale from across the estate, a core SIEM function.
Why B is wrong: Storing secrets, keys and certificates is Azure Key Vault, not a function of the Sentinel SIEM.
Why C is wrong: Configuration scoring against standards is Defender for Cloud CSPM, distinct from Sentinel data correlation.
Why D is correct: Playbook-driven automated response is the SOAR side of Sentinel, orchestrating actions on incidents.
Why E is wrong: Portal-based RDP and SSH brokering is Azure Bastion, unrelated to Sentinel's SIEM and SOAR roles.