What's changed: Deepened AZ-500 Chapter 4 (ja figures; comparison tables/scenarios/FAQ/traps/deep paragraphs in all sections)
4.2Microsoft Sentinel (SIEM / SOAR)
Understand Microsoft Sentinel, a cloud-native SIEM (security information and event management) and SOAR (automated response). It ingests broadly via data connectors, detects threats with analytics rules, and responds automatically with playbooks.
Looking at individual logs alone can’t reveal organization-wide attacks. Sentinel is a cloud SIEM/SOAR that correlates, detects, investigates, and auto-responds across many sources.
4.2.1Sentinel building blocks
- Data connectors: ingest diverse sources—Entra, Microsoft 365, Defender, other clouds/on-prem.
- Analytics rules: correlate ingested logs to detect threats and create incidents.
- Investigation/hunting: entity correlation on incidents and proactive threat hunting with KQL.
- Playbooks: automated response (SOAR) via Logic Apps—automate notifications, ticketing, isolation, etc.
Common on AZ-500: cloud-native SIEM = Microsoft Sentinel, ingest diverse sources = data connectors, correlate and create incidents = analytics rules, automated response (SOAR) = playbooks (Logic Apps). Note Sentinel runs on a Log Analytics workspace.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

