For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAzure Solutions Architect Expert (AZ-305)Azure Solutions Architect Expert AZ-305 Practice Exam 2Question 01
    Hard1 markMultiple Choice
    Domain 1.1: Logging and MonitoringDomain 1Logging and MonitoringLog AnalyticsRBAC

    AZ-305 · Question 01 · Domain 1.1: Logging and Monitoring

    Fabrikam Inc. is a global financial services company with 200 Azure subscriptions managed via a complex Management Group hierarchy. They currently operate in 5 Azure regions.

    The security team requires that all security logs, performance metrics, and application telemetry from all resources across all subscriptions be collected for threat hunting and compliance reporting. The compliance team mandates that data must be retained for 2 years, and access to logs must be strictly segregated so that regional IT teams can only query logs for resources in their respective regions.

    Which Log Analytics workspace architecture should you recommend to minimize operational overhead while meeting all security and compliance requirements?

    Answer options:

    A.

    A single centralized Log Analytics workspace with workspace-context RBAC.

    B.

    A single centralized Log Analytics workspace with resource-context RBAC.

    C.

    One Log Analytics workspace per Azure region with workspace-context RBAC.

    D.

    One Log Analytics workspace per subscription with resource-context RBAC.

    How to approach this question

    Evaluate the trade-off between centralized management and distributed access control. Resource-context RBAC is the key feature that allows centralized storage with decentralized access.

    Full Answer

    B.A single centralized Log Analytics workspace with resource-context RBAC.✓ Correct
    A single centralized Log Analytics workspace with resource-context RBAC.
    In Azure Monitor, a centralized Log Analytics workspace is generally recommended to reduce operational overhead and simplify centralized querying (e.g., for Azure Sentinel). To meet the requirement of segregated access, 'resource-context' RBAC should be used. This ensures that users can only view logs for resources they already have read access to in Azure, without needing direct access to the workspace itself.

    Common mistakes

    Candidates often choose multiple workspaces thinking it's the only way to segregate data, ignoring the capabilities of resource-context RBAC.
    All questionsQuestion 02

    Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 2

    55 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q02A healthcare organization has 500 on-premises Windows Server VMs and 300 Azure VMs. They are impl...HardQ03You are designing a security monitoring solution using Microsoft Sentinel. The compliance depar...EasyQ04Your company has a microservices application deployed across multiple Azure App Service instances...MediumQ05A defense contractor is migrating to Microsoft 365 and Azure. They have a strict security policy ...HardQ06You are designing an identity governance solution for a large enterprise using Microsoft Entra ID...Medium
    View all 55 questions →