ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 158 - SC-200 discussion

Report
Export

You have an Azure subscription that uses Microsoft Defender for Cloud and contains a storage account named storage1. You receive an alert that there was an unusually high volume of delete operations on the blobs in storage1. You need to identify which blobs were deleted. What should you review?

A.

the activity logs of storage1

Answers
A.

the activity logs of storage1

B.

the Azure Storage Analytics logs

Answers
B.

the Azure Storage Analytics logs

C.

the alert details

Answers
C.

the alert details

D.

the related entities of the alert

Answers
D.

the related entities of the alert

Suggested answer: A

Explanation:

To identify which blobs were deleted, you should review the activity logs of the storage account. The activity logs contain information about all the operations that have taken place in the storage account, including delete operations. These logs can be accessed in the Azure portal by navigating to the storage account, selecting "Activity log" under the "Monitoring" section, and filtering by the appropriate time range. You can also use

Azure Monitor and Log Analytics to query and analyze the activity logs data.

Reference:

https://docs.microsoft.com/en-us/azure/storage/common/storage-activity-logs

https://docs.microsoft.com/en-us/azure/azure-monitor/platform/activity-log-azure-storage

asked 05/10/2024
Bill May
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first