Azure Activity Log — Microsoft Azure Security Engineer (AZ-500) Practice Questions

The Azure Activity Log records all control-plane operations performed on Azure resources, capturing who did what, when, and from where at the subscription level. For AZ-500, candidates must understand how to use Activity Logs to detect unauthorized changes, investigate security incidents, and configure alerts for suspicious management operations. The log retains data for 90 days by default, and security engineers must know how to route it to a Log Analytics workspace or storage account for longer retention and SIEM integration.

Free questions on azure activity log

Which Azure feature allows you to monitor and log all API calls and administrative actions?
Free question · medium · full answer + explanation

More azure activity log questions in the full bank

Practice Microsoft Azure Security Engineer (AZ-500) Questions Free