Soru

Zorluk: OrtaMonitoring and Log Routing Solutions

An enterprise runs cloud workloads across two Azure regions: East US and North Europe.

The organization must comply with the following requirements:
- All resource diagnostic logs containing customer-identifiable information generated in North Europe must reside within the European Union due to data residency regulations.
- The central security operations center (SOC) team must analyze security and audit events from all regions collectively using Microsoft Sentinel.

Which monitoring and log routing configuration should you recommend?

  1. Create regional Log Analytics workspaces in East US and North Europe for resource diagnostic logs. Configure diagnostic settings to route resource logs to their respective regional workspaces, and route security and audit logs from both regions to a centralized Log Analytics workspace configured with Microsoft Sentinel.Cevap
  2. B
    Create a single, centralized Log Analytics workspace in the East US region. Configure all diagnostic settings, security events, and audit logs from both East US and North Europe to route to this single workspace to minimize workspace management overhead.
  3. C
    Create regional Log Analytics workspaces and a centralized Sentinel workspace. Grant the security team access to view security events by assigning Azure RBAC roles directly to the user accounts of individual security analysts in each workspace.
  4. D
    Create regional workspaces and a centralized Sentinel workspace. Implement an Azure Policy with a Deny effect to prevent the deployment of any resource that does not have diagnostic settings already configured to route logs.

Cevap

Create regional Log Analytics workspaces in East US and North Europe for resource diagnostic logs. Configure diagnostic settings to route resource logs to their respective regional workspaces, and route security and audit logs from both regions to a centralized Log Analytics workspace configured with Microsoft Sentinel.
The correct architecture uses regional workspaces (East US and North Europe) for resource diagnostic logs containing sensitive customer data, complying with European residency regulations. Simultaneously, it routes security and audit logs from both regions to a centralized workspace configured with Microsoft Sentinel, allowing the SOC team to perform unified threat analysis.

Adım Adım Çözüm

1
Analyze the data residency constraints for resource logs.
Resource diagnostic logs containing customer-identifiable information in North Europe must stay in Europe, requiring a local workspace in North Europe.
Data sovereignty regulations mandate that sensitive personal data cannot be transferred out of the region.
2
Determine the SOC requirement for centralized security analysis.
Security events and audit logs must be routed to a centralized workspace configured with Microsoft Sentinel.
Microsoft Sentinel requires a centralized Log Analytics workspace to perform effective cross-region security analytics and correlation.
3
Design the log routing architecture using diagnostic settings.
Configure Azure resources to route diagnostic logs regionally and security logs centrally.
Azure diagnostic settings support multiple destinations, allowing different categories of logs to be routed to different workspaces.

Anahtar Kavram

Log Analytics workspace design and diagnostic log routing configurations supporting both data residency and centralized security monitoring.
Tahmini Süre:1m 30s
Bu soruyu puanla