Protego field desk
Security Operations, Identity and Compliance / 25-30% of exam

L5.SIEM, XDR, SOAR & Centralized Logging Architecture

Course outlineLesson 5 of 18

Design a security operations architecture that gives SIEM, XDR, audit, and automation systems the right signals, retention, ownership, and response boundaries.

Define outcomes before data sources

Start with detection and investigation use cases, then identify the telemetry required to support them. Collecting every event without a purpose increases cost and noise. For each source, define owner, schema, latency, retention, integrity, and failure monitoring.

Combine SIEM and XDR deliberately

Microsoft Sentinel correlates broad cloud, identity, network, and third-party telemetry. Microsoft Defender XDR provides product-native detection and investigation across supported security domains. Integrate them so incidents and context reinforce each other without creating duplicate response ownership.

Centralize audit evidence

Administrative and compliance events may require different retention and access controls from operational alerts. Include Microsoft Purview Audit where Microsoft 365 activities are in scope. Protect log workspaces, export paths, and collector identities from the same administrators being monitored.

Automate safe actions

Use SOAR for repeatable enrichment, notification, containment, and ticketing. Keep destructive or business-disruptive actions behind approval until accuracy is proven. Every playbook needs an identity, scoped permissions, error handling, and an audit trail.

DecisionKey question
IngestDoes this signal support a use case?
RetainWhat investigation or compliance window applies?
AutomateIs the action reversible and sufficiently reliable?
EscalateWho owns the affected business service?
Exam Focus Points
  • Design telemetry from detection, investigation, and compliance use cases
  • SIEM supplies broad correlation while XDR supplies domain-native context
  • Protect logging identities and storage from monitored administrators
  • SOAR actions require least privilege, failure handling, and auditable approval boundaries
Knowledge Check

1. What should determine whether a data source is ingested into a SIEM?