Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium
A security administrator needs to ensure that all virtual machines in a specific Azure subscription have their diagnostic settings configured to send audit logs to a Log Analytics workspace. This requirement must be enforced automatically for new VMs and audited for existing ones. Which Azure service should be used to implement this requirement?
- AAzure Monitor activity log
- BAzure Policy
- CAzure Sentinel
- DAzure Security Center (Microsoft Defender for Cloud)
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Policy
Azure Policy is the correct service for enforcing organizational standards and assessing compliance at scale. It can be used to audit existing resources for non-compliance and automatically remediate or enforce specific configurations, such as diagnostic settings, for new resources.
Why the other options are wrong
- A. The Azure Monitor activity log records control plane operations, but doesn't enforce configurations.
- C. Azure Sentinel is a SIEM solution for collecting, analyzing, and responding to security data, not for enforcing resource configurations.
- D. Defender for Cloud provides security posture management and recommendations, but Azure Policy is the underlying enforcement engine for many of its recommendations.
Azure Policy
A service in Azure that helps enforce organizational standards and assess compliance at scale. It enables you to create, assign, and manage policies that define rules for your resources.
- Used for governance, compliance, and configuration management.
- Can audit, deny, or modify resource creation/updates.
- Supports built-in policies and custom policy definitions.
Memory trick: Policies Guard the Azure Kingdom.