Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security engineer is configuring Azure Monitor to detect unusual administrative activities within their Azure subscription. They want to receive an alert whenever a 'Delete Virtual Machine' operation is initiated by any user, excluding specific automated service principals. The alert should trigger within 5 minutes of the event occurring. Which type of alert rule should be created in Azure Monitor to meet these requirements?

  1. AMetric alert rule
  2. BActivity log alert rule
  3. CLog search alert rule
  4. DSmart detection alert rule
Show answer & explanation

Correct answer: B. Activity log alert rule

Activity log alert rules in Azure Monitor are designed to trigger alerts based on specific events in the Azure Activity Log. They are ideal for monitoring administrative operations like 'Delete Virtual Machine' and can be configured with conditions to exclude specific users or service principals.

Why the other options are wrong

  • A. Metric alert rules monitor numerical values (metrics) over time, not specific administrative operations.
  • C. Log search alert rules query data in Log Analytics workspaces. While Activity Log data can be sent to Log Analytics, using a direct Activity log alert rule is more efficient and direct for this specific scenario.
  • D. Smart detection alert rules are predefined alerts in services like Application Insights that use machine learning to detect anomalous patterns, which is not suitable for detecting a specific administrative action.

Azure Monitor Activity Log Alerts

Alert rules in Azure Monitor that trigger based on events recorded in the Azure Activity Log, which tracks control plane operations.

  • Monitors administrative operations (e.g., resource creation, deletion, updates).
  • Can filter by resource, resource group, subscription, event level, caller, etc.
  • Ideal for detecting unauthorized changes or critical administrative actions.

Memory trick: Alerts are like different 'sensors' for different 'events' in Azure.

More Manage security operations questions