QuestionQ14

Network operations, monitoring, and performance

An organization has centralized logging at its on-premises data center and needs a solution to consolidate logging from deployed cloud workloads. The organization wants to automate detection and alerting. Which of the following best meets these requirements?

Explanation

A SIEM centralizes log data from multiple environments and sources, correlates that data to detect threats or operational issues, and supports automated alerting through rules. Microsoft’s guidance describes using centralized log aggregation for cross-service correlation and configuring alert rules from aggregated multi-source logs.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!