Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

An organization uses Azure. A security analyst needs to investigate a suspicious login event. Which Azure log contains details about user sign-ins, including IP address, timestamp, and success/failure status?

⚠ Common exam trap

Many exam-takers confuse Azure Activity Logs (control-plane) with Microsoft Entra ID Sign-in logs (identity-plane), mistakenly thinking that resource-level logs capture user authentication events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Sign-in logs

Microsoft Entra ID Sign-in logs (Option B) are the correct source because they specifically capture user authentication events, including the IP address of the client, the exact timestamp of the sign-in attempt, and the success or failure status (e.g., 'Success', 'Failure', 'Interrupted'). This log is part of Microsoft Entra ID's monitoring suite and is designed for identity-related forensic investigations, unlike infrastructure or resource-level logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Monitor Metrics

    Why it's wrong here

    Azure Monitor Metrics stores only numerical time-series data (e.g., failed sign-in counts, CPU load) that is pre-aggregated and sampled. It does not retain individual authentication events, so it lacks the raw details needed to investigate a specific user's sign-in, including IP addresses, timestamps, and failure reasons. While you might see a metric spike in failed sign-ins, you cannot drill down to the underlying log entries, making it unsuitable as a source for sign-in investigation.

  • ✓

    Microsoft Entra ID Sign-in logs

    Why this is correct

    Microsoft Entra ID Sign-in logs are the canonical record of user authentication events in Microsoft Entra ID. Each entry contains the user principal name, IP address, client application, timestamp, location, conditional access policies applied, and the sign-in status (success, failure, or interrupted). These logs cover interactive and non-interactive sign-ins and are accessible via the Azure portal, Microsoft Graph API, or by streaming to a SIEM. They provide the granular evidence needed to trace exactly when, from where, and how an account was accessed.

  • ✗

    Azure Activity Logs

    Why it's wrong here

    Azure Activity Logs (also known as the Azure Monitor activity log) capture control-plane events for Azure resources, such as resource creation, deletion, or configuration changes (e.g., 'create virtual machine' or 'update network security group'). They do not capture user authentication or sign-in events at all. Even though an attacker may later modify resources, the Activity Log would only show the resource-oriented operation after authentication, not the sign-in itself, so it cannot answer 'who signed in and did they succeed'.

  • ✗

    Azure Security Center alerts

    Why it's wrong here

    Azure Security Center (now part of Microsoft Defender for Cloud) generates high-level security alerts by correlating signals from multiple sources, including sign-in logs, but it does not expose the raw sign-in log entries. These alerts are derived, curated findings like 'impossible travel activity' or 'anonymous IP sign-in', which may omit the full set of user IPs, timestamps, and statuses required for a thorough forensic review. Relying solely on Security Center alerts would miss individual sign-in events that did not trigger a detection rule, making it incomplete for a user-level authentication investigation.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.