Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy

A security operations center (SOC) analyst is investigating a series of suspicious activities reported across several Azure subscriptions. The analyst needs to quickly identify all administrative actions performed by a specific user account across these subscriptions within the last 24 hours. Which Azure service should the analyst primarily use to achieve this efficiently?

  1. AAzure Monitor Metrics
  2. BAzure Activity Log
  3. CAzure Security Center (Microsoft Defender for Cloud)
  4. DAzure Network Watcher
Show answer & explanation

Correct answer: B. Azure Activity Log

The Azure Activity Log records all administrative operations performed on resources in Azure, including who performed the action, when it occurred, and the status. This makes it the primary tool for investigating administrative actions by a specific user across subscriptions.

Why the other options are wrong

  • A. Azure Monitor Metrics collects numerical data about resource performance, not administrative operations.
  • C. While Defender for Cloud provides security recommendations and alerts, the Activity Log is the direct source for administrative action records.
  • D. Azure Network Watcher provides tools for monitoring, diagnosing, and viewing network-related issues, not administrative actions.

Azure Activity Log

A log that records events related to subscriptions and management groups in Azure, providing insight into who performed what action, when, and on which resource.

  • Records administrative operations and resource changes.
  • Includes event initiation, time, status, and affected resource.
  • Essential for auditing, compliance, and troubleshooting.

Memory trick: Activity Log: Your 'who-did-what-when' detective.

More Manage security operations questions