Microsoft Certified: DevOps Engineer ExpertImplement an instrumentation strategyMedium

A security team needs to be notified immediately if any critical Azure resource (e.g., Virtual Network, Storage Account) is deleted or modified in a way that could impact security posture. This includes changes made by administrators or automated processes. The notifications should go to a specific security operations email alias. Which type of alert rule in Azure Monitor should they configure?

  1. AMetric alert rule
  2. BLog alert rule
  3. CApplication Insights smart detection
  4. DActivity log alert rule
Show answer & explanation

Correct answer: D. Activity log alert rule

Activity log alert rules are specifically designed to monitor events in the Azure activity log, which records control-plane operations like resource creation, deletion, and modification. This is the correct choice for detecting changes to critical Azure resources.

Why the other options are wrong

  • A. Metric alerts monitor numerical performance data, not administrative operations.
  • B. Log alerts monitor data in Log Analytics workspaces, which could include some administrative logs, but Activity log alerts are purpose-built and more direct for control-plane events.
  • C. Application Insights smart detection identifies performance anomalies and failures within applications, not infrastructure changes.

Azure Activity Log Alerts

Alert rules in Azure Monitor that trigger when a specific event occurs in the Azure Activity Log, such as resource creation, deletion, or modification.

  • Monitors control-plane operations on Azure resources.
  • Can filter by resource type, operation name, resource group, etc.
  • Useful for security, compliance, and auditing.

Memory trick: Activity logs for 'who did what' on Azure resources.

More Implement an instrumentation strategy questions