Microsoft Certified: DevOps Engineer ExpertImplement an instrumentation strategyMedium
A financial services company uses Azure DevOps to manage its application lifecycle. They need to ensure that all changes to their production Azure infrastructure, such as virtual network configurations or firewall rules, are tracked and auditable. Specifically, they want to be alerted if any critical security-related resource is modified or deleted. Which Azure Monitor feature should be configured to meet this requirement?
- AAzure Activity Log Alerts
- BAzure Monitor for VMs
- CAzure Monitor Metric Alerts
- DAzure Network Watcher
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Activity Log Alerts
Azure Activity Log records all control-plane operations performed on Azure resources. Azure Activity Log Alerts allow you to trigger notifications or actions based on specific events recorded in this log, such as resource modifications or deletions, which is crucial for auditing infrastructure changes.
Why the other options are wrong
- B. Azure Monitor for VMs focuses on guest OS and VM performance, not infrastructure changes.
- C. Metric alerts monitor numerical values (e.g., CPU, memory), not control-plane operations.
- D. Azure Network Watcher provides network diagnostic and monitoring tools, not activity log alerting.
Azure Activity Log Alerts
A type of alert in Azure Monitor that notifies you when a specific event occurs in your Azure subscription's Activity Log. These events include resource creation, updates, deletion, and other administrative actions.
- Monitors control-plane operations (e.g., PUT, POST, DELETE).
- Crucial for security, compliance, and operational auditing.
- Can trigger Action Groups for various notification types.
Memory trick: Activity Log Alerts are the 'A' in 'AUDIT' for Azure changes.