Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

Which cloud service's audit logs would an investigator examine to identify who deleted a virtual machine in an Azure subscription?

⚠ Common exam trap

EC-CHFI often tests the distinction between control-plane logs (Activity Log) and authentication logs (Microsoft Entra ID Sign-in Logs), and the trap here is that candidates confuse Microsoft Entra ID Sign-in Logs (which show who logged in) with the Activity Log (which shows who performed a resource action), leading them to incorrectly choose option C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Activity Log

Azure Activity Log (formerly known as Audit Logs or Operational Logs) is the platform-level log that records all control-plane operations for Azure resources, including virtual machine creation, modification, and deletion. When a VM is deleted, the Activity Log captures the caller (user or service principal), the timestamp, the operation name (e.g., 'Microsoft.Compute/virtualMachines/delete'), and the status. An investigator would query the Activity Log to identify who initiated the deletion, making option B correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GCP Audit Logs

    Why it's wrong here

    GCP Audit Logs capture administrative and data-access activity inside Google Cloud projects, so they contain no records of an Azure VM deletion. It is tempting because GCP Audit Logs serve the same investigative purpose for Google Cloud, and would be correct had the virtual machine been deployed in GCP.

  • ✓

    Azure Activity Log

    Why this is correct

    The Azure Activity Log records subscription-level control-plane operations, including who deleted a virtual machine, when, and from where. It captures the caller identity and operation name, satisfying the investigator's need to attribute the deletion to a specific principal.

  • ✗

    Microsoft Entra ID Sign-in Logs

    Why it's wrong here

    Sign-in logs record authentication events for identities, not resource operations such as VM deletion. Azure Activity Logs capture subscription-level control-plane actions, including who deleted a virtual machine, making them the correct source for this investigation.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity within AWS accounts, so it holds no entries for an Azure subscription's virtual machine deletion. It is tempting because CloudTrail is the equivalent audit service for AWS, and would be the correct choice had the deleted VM been hosted in AWS rather than Azure.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.