Microsoft Certified: DevOps Engineer ExpertImplement an instrumentation strategyMedium
A security team needs to be notified immediately if any critical Azure resource (e.g., Virtual Network, Storage Account) is deleted or modified in a way that could impact security posture. This includes changes made by administrators or automated processes. The notifications should go to a specific security operations email alias. Which type of alert rule in Azure Monitor should they configure?
- AMetric alert rule
- BLog alert rule
- CApplication Insights smart detection
- DActivity log alert rule
Show answer & explanationAnswer & explanation
Correct answer: D. Activity log alert rule
Activity log alert rules are specifically designed to monitor events in the Azure activity log, which records control-plane operations like resource creation, deletion, and modification. This is the correct choice for detecting changes to critical Azure resources.
Why the other options are wrong
- A. Metric alerts monitor numerical performance data, not administrative operations.
- B. Log alerts monitor data in Log Analytics workspaces, which could include some administrative logs, but Activity log alerts are purpose-built and more direct for control-plane events.
- C. Application Insights smart detection identifies performance anomalies and failures within applications, not infrastructure changes.
Azure Activity Log Alerts
Alert rules in Azure Monitor that trigger when a specific event occurs in the Azure Activity Log, such as resource creation, deletion, or modification.
- Monitors control-plane operations on Azure resources.
- Can filter by resource type, operation name, resource group, etc.
- Useful for security, compliance, and auditing.
Memory trick: Activity logs for 'who did what' on Azure resources.