Courseiva

CCSP Cloud Security Operations Practice Question

A cloud security engineer needs to review who created or modified IAM policies in an Azure subscription over the past 90 days, and must retain that evidence for compliance. Which Azure-native capability should be used to collect and store these records?

⚠ Common exam trap

The trap here is assuming that posture or compliance tooling like secure score or Azure Policy provides an audit trail of who made a change.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Activity Log with a diagnostic setting to a Log Analytics workspace

The Azure Activity Log is the subscription's control-plane audit record and captures write operations such as role assignment and policy edits along with the calling identity. Exporting it via a diagnostic setting to a Log Analytics workspace provides queryable, retainable evidence, which is exactly what is needed to review IAM changes over 90 days.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud secure score

    Why it's wrong here

    Secure score aggregates posture recommendations and their relative impact; it does not provide an authoritative audit trail of individual IAM changes. It cannot identify which principal edited a specific policy, so it does not meet the evidence requirement.

  • ✓

    Azure Activity Log with a diagnostic setting to a Log Analytics workspace

    Why this is correct

    The Azure Activity Log records subscription-level control-plane operations including role assignment and policy changes, with the caller identity and timestamp. Routing it through a diagnostic setting to a Log Analytics workspace enables long-term retention and querying, satisfying the 90-day review and compliance retention needs.

  • ✗

    Azure Policy compliance reports

    Why it's wrong here

    Azure Policy evaluates resources against governance rules and reports compliance state, but it does not log the identity of the user who changed an IAM policy. Policy compliance is about resource configuration, not an immutable audit history of administrative actions.

  • ✗

    Azure Monitor metrics

    Why it's wrong here

    Azure Monitor metrics store numeric time-series data about resource performance and health, not control-plane audit events such as IAM policy changes. Metrics cannot answer who modified a role assignment, so they are unsuitable for this compliance evidence requirement.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.