Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard

A company is concerned about potential data exfiltration from their Azure Blob Storage accounts. They want to monitor all read and write operations, including who performed them, when, and from where. Which Azure monitoring service can collect and centralize these operational logs for analysis and auditing?

  1. AAzure Log Analytics (part of Azure Monitor Logs)
  2. BAzure Service Health
  3. CAzure Activity Log
  4. DAzure Monitor Metrics
Show answer & explanation

Correct answer: A. Azure Log Analytics (part of Azure Monitor Logs)

Azure Log Analytics, a component of Azure Monitor Logs, is a service that collects and centralizes logs from various Azure resources, including Blob Storage access logs. It provides advanced querying capabilities (KQL) to analyze these operational logs for detailed auditing and security monitoring, such as detecting data exfiltration.

Why the other options are wrong

  • B. Azure Service Health provides personalized alerts and guidance on Azure service issues, not operational logs for specific resource access.
  • C. Azure Activity Log records control-plane operations (e.g., creating a storage account), but not data-plane operations like individual read/write access to blobs.
  • D. Azure Monitor Metrics collects numerical data about resource performance, not detailed operational logs of read/write operations.

Azure Log Analytics

A service within Azure Monitor that collects, indexes, and stores log data from various Azure resources for advanced querying, analysis, and alerting.

  • Collects logs from many sources.
  • Supports Kusto Query Language (KQL).
  • Centralizes operational and diagnostic logs.
  • Essential for security auditing and troubleshooting.

Memory trick: Log Analytics: Your 'L' for 'Logbook' of all Azure actions.

More Describe Azure management and governance questions