Cloud workload protection vs. SIEM/SOAR vs. legacy product name
All three are "security" services and the name change from Security Center to Defender for Cloud creates additional confusion.
Deciding signal
Azure Security Center was renamed to Microsoft Defender for Cloud. They are the same product — if you see Security Center on an exam, treat it as Defender for Cloud. Defender for Cloud provides CSPM (Cloud Security Posture Management), a secure score, hardening recommendations, and Defender plans for workload-specific threat protection (VMs, databases, containers, storage). Microsoft Sentinel is a cloud-native SIEM and SOAR — it collects and correlates logs from Azure, on-premises, and third-party sources using analytics rules, detects threats with ML, manages incidents, and automates response with playbooks (Logic Apps). When the scenario involves improving resource security configurations and detecting resource-level threats, Defender for Cloud. When it involves aggregating logs for threat hunting, correlation, and automated response across a full environment, Sentinel.
Quick check
Is this assessing and protecting Azure resource configurations (Defender for Cloud / Security Center), or aggregating logs for threat detection, investigation, and automated response (Sentinel)?
Why it looks right
The Security Center → Defender for Cloud rename causes confusion. Sentinel is the correct answer for SIEM-style scenarios — log aggregation, custom detection rules, and playbook-based response — which Defender for Cloud does not provide.