Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy

A security engineer needs to analyze security logs from various Azure resources, such as virtual machines, network security groups, and Azure Key Vaults, in a centralized location. They want to perform complex queries to correlate events and identify potential threats. Which Azure service is best suited for collecting, storing, and efficiently querying these diverse security logs?

  1. AAzure Storage Account
  2. BAzure Log Analytics workspace
  3. CAzure Data Lake Storage
  4. DAzure Event Hubs
Show answer & explanation

Correct answer: B. Azure Log Analytics workspace

An Azure Log Analytics workspace is designed for centralized collection, long-term storage, and powerful querying (using KQL) of logs and metrics from various Azure resources and other sources.

Why the other options are wrong

  • A. Azure Storage Accounts can store logs but lack built-in querying capabilities for complex analysis.
  • C. Azure Data Lake Storage is for large-scale data analytics, but Log Analytics is specifically optimized for operational log data with built-in querying.
  • D. Azure Event Hubs are for real-time event ingestion, not long-term storage and complex querying of diverse logs.

Azure Log Analytics Workspace

An Azure Log Analytics workspace is a unique environment in Azure Monitor used to collect, aggregate, and analyze log data from various sources using Kusto Query Language (KQL).

  • Centralized log collection.
  • Powerful KQL querying capabilities.
  • Integrated with Azure Monitor and Microsoft Sentinel.

Memory trick: Log Analytics is the 'brain' for all your logs.

More Manage security operations questions