Suggested Answer:
You would use the Azure Activity Log, not Access Control to view which user turned off a specific virtual machine during the last 14 days. Activity logs are kept for 90 days. You can query for any range of dates, as long as the starting date isn't more than 90 days in the past. In this question, we would create a filter to display shutdown operations on the virtual machine in the last 14 days. Reference: https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-audit
Opção Descrição Registra quem desligou a VM?
Azure Access Control (IAM) Define permissões e controle de acesso aos recursos. ❌ Não registra ações específicas.
Azure Event Hubs Plataforma de ingestão de dados em tempo real (streaming de eventos). ❌ Não se aplica a esse cenário.
Azure Activity Log Log de auditoria que mostra quem fez o quê nos recursos do Azure. ✅ Sim!
Azure Service Health Monitora o status dos serviços do Azure e exibe incidentes relacionados. ❌ Não mostra ações
📘Answer: Azure Activity Log
Purpose:
Tracks control plane operations at the subscription level—like who started/stopped a VM, modified a resource group, or changed RBAC roles.
Key Features:
- Automatically enabled for all Azure subscriptions
- Retains data for 90 days by default
- Shows who did what and when (great for auditing)
- Can be viewed in the Azure Portal or queried via Azure Monitor
Purpose of:
📡 Azure Event Hubs
Purpose:
A big data streaming platform and event ingestion service. Think of it as a pipeline for collecting telemetry or log data from apps, services, or Azure resources.
Key Features:
- Ingests millions of events per second
- Used to stream data to external systems (e.g., SIEMs like Splunk, Logstash)
- Often used with Azure Monitor to export diagnostic logs or metrics
Answer: Azure Activity Log. You would use the Azure Activity Log, not Azure Monitor to view which user turned off a specific virtual machine during the last 14 days. Activity logs are kept for 90 days. You can query for any range of dates, as long as the starting date isn't more than 90 days in the past.
While Azure Activity Log is focused on logging and tracking operations and changes within Azure resources for auditing and monitoring purposes, Azure Event Hub is geared towards ingesting, processing, and managing large volumes of streaming event data from various sources for real-time analytics and processing. Event Hub is typically used as a source for SIEM solution to provide the data for analysis.
This section is not available anymore. Please use the main Exam Page.AZ-900 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
AZ900Rocks
Highly Voted 3 years, 8 months agoyesican
Highly Voted 3 years, 9 months agoRcosmos
Most Recent 6 days, 8 hours ago117975e
3 weeks, 4 days agomsmt
1 year, 7 months agokamal_004
2 years, 3 months agoSSB112
3 years agonhlegend
2 years, 2 months agoYomzie
10 months, 3 weeks agosdokmak
2 years, 11 months agoSWOng07
3 years, 8 months agoFiggy_123
3 years, 8 months ago