An enterprise runs cloud workloads across two Azure regions: East US and North Europe.
The organization must comply with the following requirements:
- All resource diagnostic logs containing customer-identifiable information generated in North Europe must reside within the European Union due to data residency regulations.
- The central security operations center (SOC) team must analyze security and audit events from all regions collectively using Microsoft Sentinel.
Which monitoring and log routing configuration should you recommend?
- Create regional Log Analytics workspaces in East US and North Europe for resource diagnostic logs. Configure diagnostic settings to route resource logs to their respective regional workspaces, and route security and audit logs from both regions to a centralized Log Analytics workspace configured with Microsoft Sentinel.Cevap
- BCreate a single, centralized Log Analytics workspace in the East US region. Configure all diagnostic settings, security events, and audit logs from both East US and North Europe to route to this single workspace to minimize workspace management overhead.
- CCreate regional Log Analytics workspaces and a centralized Sentinel workspace. Grant the security team access to view security events by assigning Azure RBAC roles directly to the user accounts of individual security analysts in each workspace.
- DCreate regional workspaces and a centralized Sentinel workspace. Implement an Azure Policy with a Deny effect to prevent the deployment of any resource that does not have diagnostic settings already configured to route logs.
Cevap
Create regional Log Analytics workspaces in East US and North Europe for resource diagnostic logs. Configure diagnostic settings to route resource logs to their respective regional workspaces, and route security and audit logs from both regions to a centralized Log Analytics workspace configured with Microsoft Sentinel.
The correct architecture uses regional workspaces (East US and North Europe) for resource diagnostic logs containing sensitive customer data, complying with European residency regulations. Simultaneously, it routes security and audit logs from both regions to a centralized workspace configured with Microsoft Sentinel, allowing the SOC team to perform unified threat analysis.
Adım Adım Çözüm
Anahtar Kavram
Log Analytics workspace design and diagnostic log routing configurations supporting both data residency and centralized security monitoring.
Tahmini Süre:1m 30s