Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Your company runs several Azure Kubernetes Service (AKS) clusters, multiple Azure App Service web apps, and serverless Azure Functions in three subscriptions. Operations needs to do the following:
Run cross-resource queries and dashboards that correlate platform and application logs from every environment.
Keep all collected logs for at least two years without exporting raw files.
Forward only high-severity error events to an on-premises SIEM that accepts Syslog over a VPN connection. Which Azure logging design meets these requirements with the least operational overhead?
Configure Diagnostic settings on every resource to send logs to a central Log Analytics workspace and to an Azure Event Hubs namespace that your SIEM reads via Syslog.
Create a separate Application Insights instance for each workload and use Azure Monitor workbooks to visualize data; export interesting logs manually to the SIEM.
Enable Microsoft Defender for Cloud and use its continuous export feature to send all logs to an Azure Storage account with a two-year lifecycle policy.
Send diagnostic logs from every resource directly to a dedicated Azure Storage account with immutable blobs and query them with Azure Data Lake analytics when needed.
A single Azure Monitor Log Analytics workspace lets you centralize platform and application logs from any Azure resource through Diagnostic settings, making cross-resource Kusto queries and workbooks possible. Log retention for a workspace can be set to as much as 730 days, so a separate archive is not required. Diagnostic settings can simultaneously stream the same logs to an Azure Event Hubs namespace; many SIEM vendors provide Syslog collectors that read from Event Hubs, allowing selective forwarding of high-severity events across the VPN. Creating separate Application Insights resources or relying only on Azure Storage would fragment data and complicate queries. Microsoft Defender for Cloud does not provide the required long-term, cross-resource log store or native Syslog streaming.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Azure Monitor Log Analytics workspace?
Open an interactive chat with Bash
How does Azure Event Hubs work with a SIEM for Syslog forwarding?
Open an interactive chat with Bash
Why are Diagnostic settings essential for cross-resource logging in Azure?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .