ExamRange
Home ExamRange Practice Tests
This module tests your ability to parse and interpret cloud-native management logs. You will learn to identify the correct fields within an Azure Activity Log schema required for attribution during a forensic investigation.

CHFI (312-49) Digital Forensics Simulation

Investigation Scenario

You have been engaged as a digital forensic investigator following a severe outage in a client's Microsoft Azure environment. A critical production Virtual Machine (VM) hosting an unbacked-up database was deleted outside of normal change management windows.

The incident response team has secured the Azure Activity Logs corresponding to the time of the deletion. To establish attribution and prove non-repudiation, you must parse the JSON schema of the deletion event to identify the exact account (User Principal Name or Service Principal) responsible for initiating the Azure Resource Manager (ARM) API call.

Evidence Collected

You extract the relevant log entry representing the VM deletion event from the Azure Activity Log via Azure Monitor. Review the structure below:

{ "authorization": { "action": "Microsoft.Compute/virtualMachines/delete", "scope": "/subscriptions/abcd-1234/resourceGroups/prod-rg/providers/Microsoft.Compute/virtualMachines/prod-db-01" }, "caller": "admin-svc@corp.onmicrosoft.com", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/55555555/", "iat": "1698765432" }, "correlationId": "a1b2c3d4-e5f6-7890-abcd-1234567890ab", "eventDataId": "b2c3d4e5-f6a7-8901-bcde-234567890abc", "eventTimestamp": "2023-11-01T04:32:15.1234567Z", "httpRequest": { "clientRequestId": "c3d4e5f6-a7b8-9012-cdef-34567890abcd", "clientIpAddress": "203.0.113.45", "method": "DELETE" }, "level": "Critical", "operationName": { "value": "Microsoft.Compute/virtualMachines/delete", "localizedValue": "Delete Virtual Machine" }, "properties": { "statusCode": "Accepted", "serviceRequestId": "d4e5f6a7-b8c9-0123-def0-4567890abcde" }, "status": { "value": "Succeeded", "localizedValue": "Succeeded" } }

Question

During a cloud-forensics investigation in Azure, an analyst is reviewing the Azure Activity Log to identify who deleted a virtual machine. Which field in the activity log entry provides the identity of the user who performed the action?

Forensic Hint: Look for the top-level JSON key in the Azure Activity Log schema that explicitly stores the User Principal Name (UPN), email address, or Service Principal Name of the entity making the Resource Manager request.

Expert Analysis

1. What the Evidence Shows

The JSON excerpt from the Azure Activity Log confirms a successful (status: Succeeded) deletion operation (Microsoft.Compute/virtualMachines/delete) on a specific resource (prod-db-01). Crucially, the top-level key caller contains the value admin-svc@corp.onmicrosoft.com, identifying the exact identity context used to execute the destructive API call from IP 203.0.113.45.

2. Identify Forensic Stage

Analysis (Attribution). The evidence has been collected; the investigator is currently analyzing the parsed artifacts to reconstruct the timeline and establish non-repudiation (identifying the attacker or compromised insider).

3. Why the Correct Answer is Correct (A)

A. caller: In the official Microsoft Azure Activity Log schema, the caller field is specifically designated to hold the identity (the User Principal Name or Service Principal Name) of the user or application that initiated the request to the Azure Resource Manager (ARM). This is the primary field an investigator relies on for attribution.

4. Why Others are Wrong

5. Real-World Forensic Action

Upon identifying the caller as a service account (admin-svc@corp.onmicrosoft.com), the investigator would immediately pivot. They would cross-reference the `clientIpAddress` against known organizational subnets, and then query Azure Active Directory (Entra ID) Sign-in Logs to determine where and how the service account credentials were recently authenticated, potentially uncovering a broader credential theft scenario.

6. MINI LESSON: Cloud Artifact Anatomy

  • Evidence Interpretation: Cloud control-plane logs differ vastly from traditional OS logs. Mastery requires memorizing the schemas (AWS CloudTrail vs. Azure Activity Logs).
  • Separation of Network and Identity: In cloud forensics, the IP address (httpRequest) and the Identity (caller) are distinct. A trusted identity can be abused from a malicious IP, or a trusted IP can be used to authenticate a compromised identity.
  • Chain of Custody: Azure Activity Logs are retained for 90 days by default. For forensic viability, they must be continuously exported to immutable blob storage or a secure Log Analytics Workspace.

Explore more CHFI simulations

Sharpen your digital forensics skills with more realistic scenarios.

View Practice Tests