AZ-305 exam dumps

AZ-305 practice question 11 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 11

Single answer

You are designing a solution for an e-commerce platform that processes orders from multiple Azure resources, including Azure App Service, Azure Functions, and Azure SQL Database. The team wants to analyze real-time transaction logs and retain them for 180 days to meet compliance requirements. They also need to forward logs to an external Security Information and Event Management (SIEM) solution for advanced threat detection. Which approach should you recommend for routing these logs in Azure?

  1. A

    Configure Azure Monitor Diagnostic Settings for each resource to send logs to both an Azure Event Hub and an Azure Storage account with the required retention policy.

  2. B

    Route logs exclusively to a Log Analytics workspace with the default retention period and no additional routing.

  3. C

    Use only Azure Storage queues to collect log data from each resource without configuring Diagnostic Settings.

  4. D

    Enable Azure Monitor Alerts to capture all log information for real-time ingestion and compliance storage.

Show answer and explanation

Correct answer: A

Explanation

When designing Azure solutions that require both near real-time log forwarding to a SIEM and long-term retention, the recommended practice is to configure Azure Monitor Diagnostic Settings at the resource level to route logs to the desired destinations. In this scenario, sending logs to an Azure Event Hub supports external SIEM ingestion, and archiving them in an Azure Storage account ensures the 180-day compliance requirement is met. For more details, refer to the Azure Monitor documentation: https://learn.microsoft.com/azure/azure-monitor/essentials/diagnostic-settings.

  • A. Correct.

    Option 1 is correct. By configuring Azure Monitor Diagnostic Settings for each resource (e.g., App Service, Functions, SQL Database), you can direct logs to both Azure Event Hub for near real-time forwarding to a SIEM and to an Azure Storage account for extended retention, satisfying compliance requirements. This approach is a best practice for routing logs in a flexible and scalable manner.

  • B. Incorrect.

    Option 2 is incorrect. While sending logs to a Log Analytics workspace is helpful for analytics, it does not provide a direct feed for an external SIEM unless you configure additional export (e.g., to Event Hub). Also, relying solely on the default retention may not meet the 180-day compliance requirement unless specifically configured in Log Analytics. Therefore, this approach alone doesn’t meet all the scenario’s needs.

  • C. Incorrect.

    Option 3 is incorrect. Azure Storage queues are typically used for messaging between application components, not for storing logs directly. Diagnostic Settings should be configured to route logs to a proper storage service (like Azure Blob Storage) or to Event Hub. Simply placing logs into queues without proper retention or direct SIEM integration won’t meet the stated requirements.

  • D. Incorrect.

    Option 4 is incorrect. Azure Monitor Alerts are designed to notify on specific metrics or conditions, not to capture and store logs comprehensively. While Alerts can help with real-time issue detection, they do not provide a mechanism for long-term log retention or full log forwarding to a SIEM.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam