Courseiva
Monitor and Maintain Azure ResourceshardMultiple ChoiceObjective-mapped

AZ-104 Monitor and Maintain Azure Resources Practice Question

You need to keep Azure activity log data for longer than the default retention period and make it available for analysis. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse the default retention period (90 days) with the ability to extend it via simple settings, not realizing that diagnostic settings are required to route the data to a persistent destination for longer retention and analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Diagnostic settings for the activity log

The default retention period for Azure activity logs is 90 days. To retain activity log data beyond this period and make it available for analysis (e.g., in a Log Analytics workspace, storage account, or Event Hubs), you must configure diagnostic settings for the activity log. This allows you to stream the log data to a destination of your choice, where you can set custom retention policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Diagnostic settings for the activity log

    Why this is correct

    Diagnostic settings for the activity log are the correct mechanism because they allow you to route Azure activity log data to a Log Analytics workspace, storage account, or Event Hub. By default, activity logs are retained for only 90 days, but configuring diagnostic settings enables you to archive that data for years or stream it to analysis tools, satisfying long-term retention and compliance requirements.

  • A resource lock on the subscription

    Why it's wrong here

    A resource lock on the subscription prevents accidental deletion or modification of Azure resources by setting a read-only or delete restriction. This protects the resources but does not affect the activity log's retention setting; the default 90-day retention remains unchanged unless you configure explicit diagnostic settings to export the log data.

    When this WOULD be correct

    A resource lock would be correct in a scenario where you need to protect a critical subscription from accidental deletion or changes, such as when implementing governance controls for a production environment.

  • An availability zone

    Why it's wrong here

    An availability zone is a physically separate datacenter group within an Azure region, designed to provide high availability for your applications by protecting against datacenter failures. It has no relationship to the activity log's storage or retention period; it only affects the resiliency of resources you deploy, so it cannot extend how long audit data is kept.

    When this WOULD be correct

    A question asking how to protect an Azure VM from a regional failure by deploying replicas across physically isolated locations would have availability zones as the correct answer.

  • A scale set autoscale policy

    Why it's wrong here

    A scale set autoscale policy controls the number of virtual machine instances based on metrics like CPU or memory, enabling horizontal scaling to handle load changes. While autoscale activity itself is recorded in the activity log, the policy does not alter the retention duration of the log data; it only influences resource capacity, not audit data persistence.

    When this WOULD be correct

    When the question asks how to automatically adjust the number of VM instances in a scale set based on CPU load or other metrics, configuring an autoscale policy is the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Diagnostic settings for the activity logCorrect answer

Why this is correct

Diagnostic settings for the activity log are the correct mechanism because they allow you to route Azure activity log data to a Log Analytics workspace, storage account, or Event Hub. By default, activity logs are retained for only 90 days, but configuring diagnostic settings enables you to archive that data for years or stream it to analysis tools, satisfying long-term retention and compliance requirements.

A resource lock on the subscriptionWrong answer — click to see why

Why this is wrong here

A resource lock on the subscription prevents accidental deletion or modification of resources, but it does not extend the retention period of activity log data or enable its analysis.

★ When this WOULD be the correct answer

A resource lock would be correct in a scenario where you need to protect a critical subscription from accidental deletion or changes, such as when implementing governance controls for a production environment.

Why candidates choose this

Candidates may confuse resource locks with data retention controls, thinking that locking the subscription preserves all data indefinitely, or they may associate locks with long-term data protection.

An availability zoneWrong answer — click to see why

Why this is wrong here

Availability zones are physically separate datacenters within an Azure region used for high availability and disaster recovery, not for extending data retention or enabling analysis of activity logs.

★ When this WOULD be the correct answer

A question asking how to protect an Azure VM from a regional failure by deploying replicas across physically isolated locations would have availability zones as the correct answer.

Why candidates choose this

Candidates may confuse 'availability' with 'data availability' or think that zones provide some form of data retention or backup capability.

A scale set autoscale policyWrong answer — click to see why

Why this is wrong here

A scale set autoscale policy manages the number of VM instances in a virtual machine scale set based on demand, not the retention or analysis of Azure activity log data.

★ When this WOULD be the correct answer

When the question asks how to automatically adjust the number of VM instances in a scale set based on CPU load or other metrics, configuring an autoscale policy is the correct answer.

Why candidates choose this

Candidates may confuse 'scale' with 'retention period' or think that scaling settings affect data storage duration, or they may misassociate autoscale with log data management.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.