Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Your company operates 20 Azure subscriptions for different business units. The security team needs every platform diagnostic log-including Activity Log, AKS control-plane logs, and Key Vault audit events-streamed to a central Log Analytics workspace in a dedicated security subscription. The same logs must also be forwarded in near real time to a third-party SIEM that ingests data from an Event Hub. Minimizing per-subscription configuration effort is a priority. Which solution should you recommend?
Deploy Azure Monitor private-link scoped data collection endpoints that push logs to the workspace and stream a copy to the SIEM.
Install the Azure Monitor agent on every resource and configure data collection rules that forward logs simultaneously to the workspace and the Event Hub.
Send all logs only to the central Log Analytics workspace and enable continuous export from that workspace to the Event Hub used by the SIEM.
Create an Azure Policy initiative that deploys diagnostic settings for every supported resource type, routing each log stream to both the central Log Analytics workspace and an Event Hub namespace in the security subscription.
Diagnostic settings are the Azure-native mechanism for routing platform and resource logs. A single diagnostic setting can simultaneously send the same log stream to up to five destinations, including a Log Analytics workspace and an Event Hub. By deploying an Azure Policy (or initiative) that automatically creates or updates diagnostic settings across all subscriptions, the security team receives the required logs in the central workspace while the SIEM consumes the same data from the Event Hub. Continuous export from Log Analytics is not supported for all log types and adds latency, and the Azure Monitor agent with data collection rules does not cover platform logs. Private link data collection endpoints are used for ingestion isolation, not routing to external systems.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Diagnostic Settings in Azure?
Open an interactive chat with Bash
What is an Azure Policy Initiative?
Open an interactive chat with Bash
How does Azure Event Hub integrate with SIEM systems?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .