Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security administrator needs to ensure that all virtual machines in a specific Azure subscription have their diagnostic settings configured to send audit logs to a Log Analytics workspace. This requirement must be enforced automatically for new VMs and audited for existing ones. Which Azure service should be used to implement this requirement?

  1. AAzure Monitor activity log
  2. BAzure Policy
  3. CAzure Sentinel
  4. DAzure Security Center (Microsoft Defender for Cloud)
Show answer & explanation

Correct answer: B. Azure Policy

Azure Policy is the correct service for enforcing organizational standards and assessing compliance at scale. It can be used to audit existing resources for non-compliance and automatically remediate or enforce specific configurations, such as diagnostic settings, for new resources.

Why the other options are wrong

  • A. The Azure Monitor activity log records control plane operations, but doesn't enforce configurations.
  • C. Azure Sentinel is a SIEM solution for collecting, analyzing, and responding to security data, not for enforcing resource configurations.
  • D. Defender for Cloud provides security posture management and recommendations, but Azure Policy is the underlying enforcement engine for many of its recommendations.

Azure Policy

A service in Azure that helps enforce organizational standards and assess compliance at scale. It enables you to create, assign, and manage policies that define rules for your resources.

  • Used for governance, compliance, and configuration management.
  • Can audit, deny, or modify resource creation/updates.
  • Supports built-in policies and custom policy definitions.

Memory trick: Policies Guard the Azure Kingdom.

More Manage security operations questions