Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
You manage 50 Azure subscriptions for a global company. The security team operates a third-party SIEM that ingests data from Azure Event Hubs. All Azure Activity logs and resource diagnostic logs must be streamed to the SIEM in near-real time and retained in Azure for at least 365 days for audit purposes. Operational effort must be kept to a minimum. Which solution should you recommend?
Assign an Azure Policy that configures diagnostic settings on all subscriptions to send logs to a centralized Log Analytics workspace (with 365-day retention) and to a shared Event Hub namespace used by the SIEM.
Create an Automation Account in each subscription that regularly exports logs to an Azure Storage account and then forwards the files to the SIEM over REST.
Deploy Azure Sentinel in every subscription and use Sentinel data connectors and playbooks to push collected logs to the SIEM.
Enable Continuous Export from Azure Monitor to an Azure Storage account and configure the SIEM to pull log files from the storage account.
Diagnostic settings can be deployed at scale by using built-in Azure Policy definitions. A single assignment can automatically enable diagnostic settings on subscriptions and resources, routing platform logs and metrics to multiple destinations: a Log Analytics workspace (where retention can be configured for 365 days or longer) and an Event Hub namespace. The workspace satisfies the audit-retention requirement, while the Event Hub feed is consumed by the SIEM. The solution is entirely managed and requires no custom code or ongoing maintenance. The other options either rely on custom runbooks, unsupported continuous export paths, or duplicate Sentinel deployments and therefore impose higher operational overhead or do not meet the technical requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Policy, and how does it work for automating settings like diagnostic configuration?
Open an interactive chat with Bash
What is an Azure Event Hub namespace, and why is it used in this solution?
Open an interactive chat with Bash
Why is a centralized Log Analytics workspace recommended for log retention in this solution?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .