Hard1 markMultiple Choice
Domain 1.1: Logging and MonitoringDomain 1Logging and MonitoringAzure LighthouseMicrosoft Sentinel

AZ-305 · Question 02 · Domain 1.1: Logging and Monitoring

Fabrikam Inc. is a Managed Service Provider (MSP) managing Azure environments for 50 different enterprise customers. Each customer has their own Microsoft Entra ID (Azure AD) tenant and multiple Azure subscriptions.

Fabrikam needs to implement a centralized security monitoring and incident response solution. The Fabrikam Security Operations Center (SOC) team must be able to view alerts, hunt for threats, and run automated playbooks across all 50 customer tenants from a single pane of glass. Customers must retain ownership of their data, and Fabrikam must not require guest accounts in customer tenants.

Which combination of Azure services should you recommend?

Answer options:

A.

Azure B2B Collaboration and Microsoft Defender for Cloud

B.

Azure Lighthouse and Microsoft Sentinel

C.

Azure Arc and Azure Monitor Workbooks

D.

Microsoft Entra ID B2C and Microsoft Sentinel

How to approach this question

Identify the requirement for cross-tenant management without guest accounts (Azure Lighthouse) and the requirement for SIEM/SOAR capabilities (Microsoft Sentinel).

Full Answer

B.Azure Lighthouse and Microsoft Sentinel✓ Correct
Azure Lighthouse and Microsoft Sentinel
Azure Lighthouse provides delegated resource management, allowing MSPs to manage resources across multiple customer tenants natively without B2B guest accounts. Microsoft Sentinel is Azure's cloud-native SIEM and SOAR solution. When combined, a SOC can use Sentinel in their managing tenant to query and analyze data residing in customer workspaces via Lighthouse.

Common mistakes

Confusing Azure B2B (which creates guest users) with Azure Lighthouse (which uses delegated access).

Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 3

55 questions · hints · full answers · grading

More questions from this exam