Microsoft Azure Solutions Architect Expert AZ-305 Practice Question

You are designing the log-routing strategy for Contoso, which operates five Azure subscriptions under a single management group. The security team requires that:

  • All Azure Activity Logs and resource diagnostic logs must remain searchable in Azure for at least 90 days for troubleshooting.
  • The same logs must be streamed in near real time to an on-premises SIEM that ingests Syslog over UDP.
  • The solution must rely only on built-in Azure capabilities and minimize ongoing administration. Which approach should you recommend?
  • Create a single Azure Monitor diagnostic setting at the management-group level that routes all Activity and resource diagnostic logs to a centralized Log Analytics workspace (90-day retention) and simultaneously streams them to an Azure Event Hub from which the on-premises SIEM pulls Syslog data.

  • Configure each subscription to archive Activity and diagnostic logs to an Azure Storage account, then use an hourly Azure Data Factory pipeline to copy the blobs to the on-premises environment for ingestion by the SIEM.

  • Install Logstash agents on every virtual machine and Azure Arc-enabled resource to forward operating-system logs directly to the on-premises Syslog server; rely on Azure Storage lifecycle policies to keep any required data for 90 days.

  • Enable Azure Monitor to export Activity and diagnostic logs to an Azure Service Bus queue and configure the SIEM to read messages from the queue while setting the workspace retention to 90 days.

Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot