Microsoft Certified Identity And Access Administrator Associate · Free Practice Question Easy
Question 9
Your organization has recently experienced what it believes to be a security breach. One of the organization's Azure Administrators may have accessed his AD account by a third party. As part of your investigation, you must review everything this administrator account has done in your directory. Where can you go to view this information?
-
A
Microsoft Entra ID Sign-ln Logs
-
B
Microsoft Entra ID Audit Logs
-
C
Microsoft Defender for Cloud
-
D
Microsoft Sentinel
Reveal correct answer
Correct answer: B
Explanation
Option A is not the correct choice, as the Azure Active Directory Sign-in logs will only display the administrator's successful and unsuccessful sign-in attempts without showing the actions performed by the administrator's account. Therefore, this choice does not meet your requirements.
Option B is correct because the Azure Active Directory Audit Logs allow you to view all actions an administrator performs in your directory. Thus, this selection meets your requirements.
Option C is not the correct choice, as Microsoft Defender for Cloud is a hub that primarily enhances an organization's security posture by providing security-related recommendations. However, this tool cannot view actions taken by the administrator's account. Therefore, this selection does not meet your requirements.
Option D is not the correct choice. Microsoft Sentinel is a scalable, cloud-native security orchestration, automation, and response (SOAR) solution. This choice does not meet the requirement of the question.
If you want to learn more, go to:
Learn about the audit logs in Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
