Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingEasy
A company is implementing a new security strategy for its Azure environment. They want to ensure that all administrative actions performed on Azure resources are logged, auditable, and traceable to the individual who performed them. Which Azure service helps achieve this requirement?
- AAzure Monitor
- BAzure Advisor
- CAzure Activity Log
- DAzure Security Center
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Activity Log
The Azure Activity Log is a platform log that records events at the subscription level, including administrative operations and changes made to resources. It helps track who performed what action, when, and from where, making it crucial for auditing and traceability.
Why the other options are wrong
- A. Azure Monitor collects and analyzes metrics and logs from various Azure resources, but the Activity Log is specifically for administrative actions.
- B. Azure Advisor provides recommendations for optimizing Azure resources, not for logging administrative actions.
- D. Azure Security Center (now Microsoft Defender for Cloud) provides cloud security posture management and threat protection, not primarily for logging administrative actions.
Azure Activity Log
A platform log in Azure that records events at the subscription level, detailing administrative operations and changes made to resources.
- Records administrative actions (who, what, when, where)
- Provides historical data for auditing
- Helps track changes to resources
- Part of Azure Monitor, but distinct for control plane events
Memory trick: Activity Log: Who did what, when, and where, for auditing clarity.