Microsoft Certified: Azure Administrator AssociateMonitor and maintain Azure resourcesMedium

A security auditor requires a company to retain all Azure Activity Log data for a period of 1 year for compliance purposes. The data needs to be stored in a cost-effective manner and be accessible for future auditing queries. Which destination should be configured in the Diagnostic Settings for the Activity Log?

  1. AAzure Monitor Metrics
  2. BAzure Storage account
  3. CLog Analytics workspace
  4. DAzure Event Hubs
Show answer & explanation

Correct answer: B. Azure Storage account

An Azure Storage account is the most cost-effective solution for long-term archival of Activity Log data, especially when it needs to be retained for a full year primarily for compliance and potential future access rather than immediate, interactive querying.

Why the other options are wrong

  • A. Azure Monitor Metrics stores numerical time-series data, not the detailed event logs found in the Activity Log.
  • C. Log Analytics workspace is excellent for interactive querying and analysis but can be more expensive than a storage account for simple long-term archival.
  • D. Azure Event Hubs is for streaming data to other services for real-time processing, not for long-term archival storage.

Azure Activity Log Diagnostic Settings to Storage Account

Configuring Azure Activity Log data to be exported to an Azure Storage account for long-term, cost-effective archival and compliance retention.

  • Cost-effective for long retention periods.
  • Data is stored as JSON blobs.
  • Good for compliance and infrequent auditing access.

Memory trick: Archive logs to storage, cheap and long, for audits strong.

More Monitor and maintain Azure resources questions