Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
You are designing a centralized logging solution for a company that runs several hundred Azure virtual machines, Azure Kubernetes Service clusters, and Azure SQL databases distributed across 20 subscriptions. Security policy requires that:
All platform and workload logs are queryable within five minutes of creation.
Log data must be retained for at least seven years to satisfy regulatory audits.
Administrators will use Kusto Query Language (KQL) to troubleshoot and create alert rules. Which approach meets the requirements while keeping administrative overhead low?
Deploy an Azure HDInsight cluster with Kafka to collect logs and store them in Azure Data Lake Storage, using Hive queries for reporting.
Send all diagnostic and activity logs to a single Log Analytics workspace configured for short-term retention, and enable Azure Monitor data export to an Azure Storage account that uses lifecycle policies for seven-year archival.
Write logs directly to an Azure Storage account in the Cool tier and use Azure Synapse serverless SQL pool to query the data when needed.
Create diagnostic settings on every resource to stream logs to Azure Event Hubs, then ingest the data into a third-party SIEM for storage and analysis.
A Log Analytics workspace provides near real-time ingestion and a rich KQL query experience that administrators already use for alerting. Retaining only the recent data (for example, 30-90 days) in the workspace keeps ingestion and query costs predictable. Azure Monitor data export (or the legacy Continuous Export) can automatically copy every newly ingested record to a storage account, where lifecycle management policies move the data to Cool or Archive tiers for inexpensive seven-year retention. Event Hubs, HDInsight, or direct Storage ingestion would require additional infrastructure or prevent KQL-based alerting, and Synapse-based querying of archived blobs does not deliver the five-minute latency the operations team needs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Kusto Query Language (KQL)?
Open an interactive chat with Bash
How does Azure Monitor data export work?
Open an interactive chat with Bash
What is an Azure Log Analytics workspace?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .