Medium1 markMultiple Choice
Domain 1.1: Logging and MonitoringDomain 1.1Azure MonitorLog Analytics

AZ-305 · Question 01 · Domain 1.1: Logging and Monitoring

Contoso Ltd is a global manufacturing company with 50,000 employees. They operate a mix of on-premises infrastructure and Azure across 50 subscriptions. The company needs to improve security posture to meet ISO 27001 compliance. You need to design a centralized logging solution. The solution must support querying across all subscriptions, retain security logs for 2 years for compliance, support custom alerts, and minimize administrative overhead. Which architecture should you recommend?

Answer options:

A.

A single centralized Log Analytics workspace.

B.

One Log Analytics workspace per subscription.

C.

One Log Analytics workspace per Azure region.

D.

Azure Storage accounts with lifecycle management.

How to approach this question

Evaluate the trade-offs between centralized and distributed logging architectures.

Full Answer

A.A single centralized Log Analytics workspace.✓ Correct
A single centralized Log Analytics workspace.
For enterprise environments prioritizing low administrative overhead and centralized querying, a single Log Analytics workspace is recommended unless data sovereignty laws dictate otherwise.

Common mistakes

Choosing per-region workspaces without a strict data residency requirement.

Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 6

55 questions · hints · full answers · grading

More questions from this exam