Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy
A security analyst is investigating a series of suspicious activities in Azure. They need to find all 'Delete' operations performed on Azure Key Vaults within the last 7 days across multiple subscriptions. Which Azure service should the analyst primarily use to query this information?
- AAzure Sentinel
- BAzure Resource Graph
- CAzure Monitor Activity Log
- DAzure Security Center (Microsoft Defender for Cloud)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Monitor Activity Log
The Azure Activity Log records all control-plane operations (e.g., create, update, delete) performed on Azure resources. This is the primary source for investigating 'Delete' operations.
Why the other options are wrong
- A. Azure Sentinel aggregates logs, but the Activity Log is the direct source of this type of operational event.
- B. Azure Resource Graph queries resource properties and configuration, not operational events like 'Delete'.
- D. Defender for Cloud provides security posture management and threat protection, but the Activity Log is the source for operation details.
Azure Activity Log
The Azure Activity Log provides a record of control-plane events (operations on resources) that occur in Azure, including who, what, when, and where for any write or delete operation.
- Records all control-plane operations.
- Useful for auditing and troubleshooting resource changes.
- Can be queried, exported, and used to create alerts.
Memory trick: Activity Log shows 'who did what'.