Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Your company has 50 Azure subscriptions in a single tenant. Compliance requires that all Azure Activity logs from every subscription be retained for three years and forwarded in near-real time to an on-premises SIEM. You must meet these requirements with the least ongoing administrative effort and ensure that any new subscriptions created in the future are covered automatically. Which solution should you recommend?
Assign a single Azure Policy at the tenant root that deploys a diagnostic setting in every subscription to route Activity logs to a central storage account (with a three-year lifecycle policy) and to a shared Event Hub namespace for SIEM ingestion.
Deploy a dedicated Log Analytics workspace in every subscription, enable Continuous Export to a storage account, and configure a Logic App in each subscription to forward logs to the SIEM.
Stream Azure AD audit and sign-in logs to a central Log Analytics workspace and rely on the default 90-day Activity log retention while exporting the workspace data to the SIEM.
Create an Automation Account runbook in each subscription that exports Activity logs daily to a shared storage account and then writes the data to an Event Hub.
Create a single Azure Policy assignment at the tenant (root management-group) scope that deploys a diagnostic setting resource in every subscription. The policy-deployed diagnostic setting sends each subscription's Activity log both to a central Azure Storage account-where a lifecycle management policy keeps the data for three years-and to a shared Event Hub namespace that the on-premises SIEM consumes in near real time. This approach scales automatically to future subscriptions and avoids per-subscription manual configuration. The other options either rely on manual or per-subscription automation, add unnecessary complexity, or fail to meet the retention or near-real-time forwarding requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Azure Policy and how does it help in this solution?
Open an interactive chat with Bash
What is a diagnostic setting in Azure and why is it critical here?
Open an interactive chat with Bash
How does the lifecycle policy on the storage account work?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .