Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
You manage 40 Azure subscriptions that belong to a single tenant. The security team uses an on-premises Splunk installation and must receive all Azure Activity log events from every subscription and all Azure AD sign-in log entries within minutes. They also require that a raw, immutable copy of the same logs be retained in Azure for at least two years at the lowest possible cost. Which logging architecture should you recommend?
Enable Azure Sentinel in each subscription and install a Splunk Universal Forwarder on the Sentinel VMs to pull data from the workspaces.
Create a diagnostic setting in each subscription to send the Azure Activity log to a central Event Hub namespace and to a storage account in a dedicated logging subscription, and configure a single Azure AD diagnostic setting to send sign-in logs to the same destinations.
Stream Activity logs from each subscription to individual storage accounts, then use Azure Data Factory pipelines to copy log files both to Splunk and to a long-term archive account.
Deploy a Log Analytics workspace in each subscription, collect both log types into the workspace, and use Continuous Export from every workspace to separate Event Hubs that Splunk will poll.
Configure an Azure Monitor diagnostic setting in every subscription to stream the Azure Activity log to a central Event Hub namespace and simultaneously archive it to a central storage account that has a lifecycle policy moving data to the Archive tier for two-year retention at minimal cost. In the Azure AD tenant, create a single diagnostic setting that streams Azure AD sign-in logs to the same Event Hub namespace and storage account. Splunk can ingest the near real-time stream from the Event Hub, while the storage account maintains an immutable, low-cost archive. The other options introduce additional cost, latency, or administrative overhead without meeting both the real-time SIEM and long-term retention requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Azure Event Hub, and why is it used in this architecture?
Open an interactive chat with Bash
How does Azure Storage ensure a low-cost, immutable archive for logs?
Open an interactive chat with Bash
What are Azure Monitor diagnostic settings, and why are they important for this solution?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .