Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security engineer is investigating a series of suspicious activities detected in Azure. They need to correlate events across different Azure services, such as virtual machine logs, network security group flow logs, and Azure Active Directory sign-in events, to build a comprehensive timeline of the attack. Which service provides the centralized log collection and powerful query language necessary for this multi-source correlation?

  1. AAzure Activity Log
  2. BAzure Monitor Log Analytics workspace
  3. CAzure Resource Graph
  4. DAzure Service Health
Show answer & explanation

Correct answer: B. Azure Monitor Log Analytics workspace

An Azure Monitor Log Analytics workspace acts as a central repository for logs from various Azure resources. It leverages Kusto Query Language (KQL) which is powerful enough to query and correlate data from diverse sources, making it ideal for security investigations and building attack timelines.

Why the other options are wrong

  • A. Azure Activity Log records control-plane events, but doesn't collect guest OS logs, flow logs, or other diagnostic logs for deep correlation.
  • C. Azure Resource Graph allows querying Azure resource metadata, not the detailed operational or security logs needed for correlation.
  • D. Azure Service Health provides information about Azure service incidents, not detailed security logs from specific resources.

Log Analytics for Security

Azure Monitor Log Analytics workspaces serve as a central hub for collecting and analyzing operational and security logs from a wide array of Azure resources, hybrid environments, and other cloud providers. Its Kusto Query Language (KQL) enables powerful correlation and analysis for security investigations.

  • Centralized log collection from diverse sources.
  • Uses Kusto Query Language (KQL) for advanced querying.
  • Essential for security investigations and threat hunting.
  • Underpins services like Microsoft Sentinel and Defender for Cloud.

Memory trick: Log Analytics collects all logs for deep insight.

More Manage security operations questions