4Manage Security Operations
- 4.1Logging, Monitoring, and Security Alerts
Understand Azure Monitor, the Log Analytics workspace, and diagnostic settings as the foundation of security operations. Recording what happened and collecting/analyzing/retaining logs is the prerequisite for detection and investigation.
- 4.2Microsoft Sentinel (SIEM / SOAR)
Understand Microsoft Sentinel, a cloud-native SIEM (security information and event management) and SOAR (automated response). It ingests broadly via data connectors, detects threats with analytics rules, and responds automatically with playbooks.
- 4.3Governance and Compliance
Understand Azure Policy to technically enforce organizational rules, Azure Blueprints to apply bundled configuration templates (note: deprecated and slated for retirement in July 2026; the successor is Azure Deployment Stacks with Azure Policy), and Defender for Cloud’s regulatory compliance to visualize alignment with standards. Keep large environments consistently secure.

