AZ-305 · Question 03 · Domain 1.1: Logging and Monitoring
A financial institution generates 5 TB of telemetry and audit logs daily across its Azure environment.
The company has the following requirements for log data:
- Security audit logs must be queried frequently for the first 30 days for immediate incident response.
- Application debug logs are rarely queried but must be retained for 7 years to meet compliance regulations.
- The overall cost of log ingestion and retention must be minimized.
Which TWO actions should you recommend to optimize the architecture? (Select TWO)
A financial institution generates 5 TB of telemetry and audit logs daily across its Azure environment.
The company has the following requirements for log data:
- Security audit logs must be queried frequently for the first 30 days for immediate incident response.
- Application debug logs are rarely queried but must be retained for 7 years to meet compliance regulations.
- The overall cost of log ingestion and retention must be minimized.
Which TWO actions should you recommend to optimize the architecture? (Select TWO)
Answer options:
Configure the Log Analytics workspace to use the Basic Logs data plan for application debug logs.
Export all logs immediately to an Azure Storage account using the Hot access tier.
Configure a data retention policy to move logs to Archive tier after 30 days.
Use Azure Data Explorer (Kusto) as the primary ingestion point for all security audit logs.
Configure the Log Analytics workspace to use the Analytics data plan for all log types.
How to approach this question
Full Answer
Common mistakes
Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 3
55 questions · hints · full answers · grading
Expert