AZ-305 exam dumps

AZ-305 practice question 8 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 8

Select 2

Your organization is migrating a multi-tier application to Azure. They want to centralize logs from various Azure resources in near real-time for consolidated monitoring and advanced analytics. Additionally, parts of the security team need to send certain logs to an external SIEM. Which of the following strategies should you recommend? (Choose two.)

  1. A

    Configure Diagnostic Settings on each resource to send logs directly to a single Log Analytics workspace.

  2. B

    Enable only Azure VM boot diagnostics, storing logs in Azure Storage for each virtual machine.

  3. C

    Set up Diagnostic Settings to stream logs to Azure Event Hubs and then ingest them into the same Log Analytics workspace.

  4. D

    Rely solely on the Azure Activity Log at the subscription level to capture and consolidate logs automatically.

Show answer and explanation

Correct answers: A, C

Explanation

To route logs for advanced analytics and external integration, use Azure Monitor Diagnostic Settings. Sending logs to a Log Analytics workspace provides centralized storage and querying, while setting up an Event Hub stream allows near real-time forwarding to external tools. For further guidance, see Azure Monitor documentation at https://learn.microsoft.com/azure/azure-monitor/.

  • A. Correct.

    Option 1 is correct. Configuring Diagnostic Settings to send resource logs directly to a Log Analytics workspace is a common best practice for centralized log collection and allows for advanced analytics with KQL.

  • B. Incorrect.

    Option 2 is incorrect. Enabling boot diagnostics stores logs only for VM startup and troubleshooting issues. This does not provide a comprehensive or centralized logging solution for all workloads.

  • C. Correct.

    Option 3 is correct. Streaming logs to an Event Hub and then ingesting them into a Log Analytics workspace is useful for real-time integration with external SIEMs or advanced analytics tools, ensuring logs can be routed to multiple destinations.

  • D. Incorrect.

    Option 4 is incorrect. Azure Activity Log captures only subscription-level events, such as resource creation or modification, and cannot replace the need for comprehensive resource-level log routing.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam