Microsoft Certified: Azure Administrator AssociateMonitor and maintain Azure resourcesMedium
A security auditor requires a company to retain all Azure Activity Log data for a period of 1 year for compliance purposes. The data needs to be stored in a cost-effective manner and be accessible for future auditing queries. Which destination should be configured in the Diagnostic Settings for the Activity Log?
- AAzure Monitor Metrics
- BAzure Storage account
- CLog Analytics workspace
- DAzure Event Hubs
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Storage account
An Azure Storage account is the most cost-effective solution for long-term archival of Activity Log data, especially when it needs to be retained for a full year primarily for compliance and potential future access rather than immediate, interactive querying.
Why the other options are wrong
- A. Azure Monitor Metrics stores numerical time-series data, not the detailed event logs found in the Activity Log.
- C. Log Analytics workspace is excellent for interactive querying and analysis but can be more expensive than a storage account for simple long-term archival.
- D. Azure Event Hubs is for streaming data to other services for real-time processing, not for long-term archival storage.
Azure Activity Log Diagnostic Settings to Storage Account
Configuring Azure Activity Log data to be exported to an Azure Storage account for long-term, cost-effective archival and compliance retention.
- Cost-effective for long retention periods.
- Data is stored as JSON blobs.
- Good for compliance and infrequent auditing access.
Memory trick: Archive logs to storage, cheap and long, for audits strong.