Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy

A security analyst is investigating a series of suspicious activities in Azure. They need to find all 'Delete' operations performed on Azure Key Vaults within the last 7 days across multiple subscriptions. Which Azure service should the analyst primarily use to query this information?

  1. AAzure Sentinel
  2. BAzure Resource Graph
  3. CAzure Monitor Activity Log
  4. DAzure Security Center (Microsoft Defender for Cloud)
Show answer & explanation

Correct answer: C. Azure Monitor Activity Log

The Azure Activity Log records all control-plane operations (e.g., create, update, delete) performed on Azure resources. This is the primary source for investigating 'Delete' operations.

Why the other options are wrong

  • A. Azure Sentinel aggregates logs, but the Activity Log is the direct source of this type of operational event.
  • B. Azure Resource Graph queries resource properties and configuration, not operational events like 'Delete'.
  • D. Defender for Cloud provides security posture management and threat protection, but the Activity Log is the source for operation details.

Azure Activity Log

The Azure Activity Log provides a record of control-plane events (operations on resources) that occur in Azure, including who, what, when, and where for any write or delete operation.

  • Records all control-plane operations.
  • Useful for auditing and troubleshooting resource changes.
  • Can be queried, exported, and used to create alerts.

Memory trick: Activity Log shows 'who did what'.

More Manage security operations questions