StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 4: Manage and monitor security posture

Microsoft Sentinel workspace design, data connectors, Azure Monitor Agent with data collection rules, Syslog and CEF, Windows security events

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Microsoft Sentinel is Microsoft's cloud-native security information and event management (SIEM) and security orchestration, automation and response (SOAR) solution. It is enabled on top of a Log Analytics workspace, where all collected data is stored and queried with KQL. Sentinel is increasingly managed from the Microsoft Defender portal alongside Defender XDR, though the concepts are the same as in the Azure portal.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan