Which Azure Monitor feature should you use to identify the user account that deleted a virtual machine 15 days ago?
Choose an answer
Tap an option to check your answer.
Correct answer: Activity Log.
Why this is the answer
The Activity Log (formerly Azure Audit Logs or Operational Logs) records all control-plane operations performed on resources in your Azure subscription, including creation, updates, and deletions. This makes it the ideal tool for identifying who deleted a virtual machine and when, even for events that occurred 15 days ago, as it retains data for 90 days. Application Logs are for application-specific events. Metrics provide numerical values about resource performance, not operational events. Logs (referring to Azure Monitor Logs or Log Analytics) is a broader service that can ingest various log types, but the specific log type for control-plane operations is the Activity Log.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed