Microsoft Azure Security Technologies (AZ-500)

Disable ads (and more) with a membership for a one time $4.99 payment

Question: 1 / 85

To find out who removed a virtual machine fifteen days ago, which Azure Monitor option would you use?

Application Log

Metrics

Activity Log

Using the Activity Log in Azure Monitor is the most suitable choice for tracking changes made to resources, such as the removal of a virtual machine. The Activity Log records all control-plane events within a subscription, including operations like creating, updating, and deleting resources. This log provides details such as the who, what, when, and where of the actions taken on your resources, making it ideal for auditing purposes. Therefore, by consulting the Activity Log, you can identify which user or system performed the deletion of the virtual machine fifteen days ago.

Other options are less appropriate for this scenario. Application Logs typically focus on the internal logging within applications or services rather than tracking changes to Azure resources. Metrics concentrate on the performance and operational data of resources, like CPU or memory usage, rather than changes to the resources themselves. Logs encompass a broader range of information but often refer to specific diagnostic information and not to the control actions taken on resources, which further confirms that the Activity Log is the most relevant choice for auditing deletions.

Logs

Next

Report this question