AZ-500 · Question #55
Drag and Drop Question You have an Azure subscription that contains 100 virtual machines. Azure Diagnostics is enabled on all the virtual machines. You are planning the monitoring of Azure services…
The correct answer is Activity log; Logs. The Activity Log records subscription-level events such as when a resource was created, modified, or deleted, along with the identity of who performed the action - making it the correct tool to identify who deleted a virtual machine up to 90 days ago. Logs (Log Analytics /…
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- Activity log
- Logs
Explanation
The Activity Log records subscription-level events such as when a resource was created, modified, or deleted, along with the identity of who performed the action - making it the correct tool to identify who deleted a virtual machine up to 90 days ago. Logs (Log Analytics / Azure Monitor Logs) collects and queries detailed telemetry data including Windows Security Event logs forwarded from virtual machines via the Log Analytics agent or Azure Diagnostics, making it the right choice for querying security events on a Windows Server 2016 VM. These two tools serve distinct but complementary purposes within Azure Monitor.
Topics
Community Discussion
No community discussion yet for this question.
