Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard
A security engineer is investigating a potential insider threat. They need to analyze changes made to Azure resources by a specific user account over the last week, focusing on any resource deletions, role assignment changes, or modifications to network security group (NSG) rules. Which Azure Monitor log source should the engineer query to find this information?
- AAzure Active Directory audit logs
- BAzure Network Watcher flow logs
- CDiagnostic logs from individual resources
- DAzure Activity Log
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Activity Log
The Azure Activity Log (formerly Azure Audit Logs) records all control plane operations performed on Azure resources, including resource creations, deletions, updates, and role assignment changes. This log is specifically designed to track who did what, when, and where for management operations, making it ideal for investigating changes to resources and role assignments.
Why the other options are wrong
- A. Azure Active Directory audit logs primarily track identity-related operations within Azure AD (e.g., user creations, group modifications), not direct resource management operations.
- B. Azure Network Watcher flow logs record network traffic passing through NSGs, not changes made to the NSG rules themselves.
- C. Diagnostic logs from individual resources (e.g., VM boot diagnostics, storage access logs) provide operational insights *within* a resource, not who made management changes *to* the resource.
Azure Activity Log
A log in Azure Monitor that records events at the subscription level, detailing operations performed on resources, by whom, when, and their status.
- Tracks control plane operations (management events).
- Includes resource creation, deletion, updates, and RBAC changes.
- Crucial for auditing, troubleshooting, and security investigations related to resource management.
Memory trick: Activity Logs Show Who Did What to Resources.