Your organization is implementing Microsoft Sentinel and needs to ensure that incident response activities are compliant with regulatory requirements. You need to track and document all changes made to analytics rules and playbooks. Which TWO features should you enable?
The Azure Activity log is the subscription-level platform log that records administrative operations on Azure resources, including every write (PUT, POST, PATCH) against Sentinel analytics rules, playbooks, and data connectors. Each entry captures the resource ID, the operation name, the initiating principal, and a timestamp, giving you a comprehensive compliance audit trail. To meet compliance requirements, you would enable diagnostic settings to export this log to a Log Analytics workspace for long-term retention and alerting.
Why this answer
Activity logs (Azure Monitor) record all management-plane operations, including changes to analytics rules and playbooks, while Azure Resource Change History (Change tracking) captures resource-level modifications. Together they provide comprehensive audit trails for regulatory compliance. Workbooks (A) are for visualization, Automation rules (B) trigger responses but don't log changes themselves, and Microsoft Purview (E) is for broader data governance, not operational change tracking.
Exam trap
Candidates often confuse automation rules or workbooks as change-tracking tools. Remember that only Azure-native logging services (Activity Logs and Change History) provide the audit trail required for regulatory compliance.