CCSP Cloud Security Operations Practice Question
A cloud security engineer needs to review who created or modified IAM policies in an Azure subscription over the past 90 days, and must retain that evidence for compliance. Which Azure-native capability should be used to collect and store these records?
⚠ Common exam trap
The trap here is assuming that posture or compliance tooling like secure score or Azure Policy provides an audit trail of who made a change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Activity Log with a diagnostic setting to a Log Analytics workspace
The Azure Activity Log is the subscription's control-plane audit record and captures write operations such as role assignment and policy edits along with the calling identity. Exporting it via a diagnostic setting to a Log Analytics workspace provides queryable, retainable evidence, which is exactly what is needed to review IAM changes over 90 days.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud secure score
Why it's wrong here
Secure score aggregates posture recommendations and their relative impact; it does not provide an authoritative audit trail of individual IAM changes. It cannot identify which principal edited a specific policy, so it does not meet the evidence requirement.
- ✓
Azure Activity Log with a diagnostic setting to a Log Analytics workspace
Why this is correct
The Azure Activity Log records subscription-level control-plane operations including role assignment and policy changes, with the caller identity and timestamp. Routing it through a diagnostic setting to a Log Analytics workspace enables long-term retention and querying, satisfying the 90-day review and compliance retention needs.
- ✗
Azure Policy compliance reports
Why it's wrong here
Azure Policy evaluates resources against governance rules and reports compliance state, but it does not log the identity of the user who changed an IAM policy. Policy compliance is about resource configuration, not an immutable audit history of administrative actions.
- ✗
Azure Monitor metrics
Why it's wrong here
Azure Monitor metrics store numeric time-series data about resource performance and health, not control-plane audit events such as IAM policy changes. Metrics cannot answer who modified a role assignment, so they are unsuitable for this compliance evidence requirement.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.