AZ-104 Monitor and Maintain Azure Resources Practice Question
You need to keep Azure activity log data for longer than the default retention period and make it available for analysis. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse the default retention period (90 days) with the ability to extend it via simple settings, not realizing that diagnostic settings are required to route the data to a persistent destination for longer retention and analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Diagnostic settings for the activity log
The default retention period for Azure activity logs is 90 days. To retain activity log data beyond this period and make it available for analysis (e.g., in a Log Analytics workspace, storage account, or Event Hubs), you must configure diagnostic settings for the activity log. This allows you to stream the log data to a destination of your choice, where you can set custom retention policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Diagnostic settings for the activity log
Why this is correct
Diagnostic settings for the activity log are the correct mechanism because they allow you to route Azure activity log data to a Log Analytics workspace, storage account, or Event Hub. By default, activity logs are retained for only 90 days, but configuring diagnostic settings enables you to archive that data for years or stream it to analysis tools, satisfying long-term retention and compliance requirements.
- ✗
A resource lock on the subscription
Why it's wrong here
A resource lock on the subscription prevents accidental deletion or modification of Azure resources by setting a read-only or delete restriction. This protects the resources but does not affect the activity log's retention setting; the default 90-day retention remains unchanged unless you configure explicit diagnostic settings to export the log data.
When this WOULD be correct
A resource lock would be correct in a scenario where you need to protect a critical subscription from accidental deletion or changes, such as when implementing governance controls for a production environment.
- ✗
An availability zone
Why it's wrong here
An availability zone is a physically separate datacenter group within an Azure region, designed to provide high availability for your applications by protecting against datacenter failures. It has no relationship to the activity log's storage or retention period; it only affects the resiliency of resources you deploy, so it cannot extend how long audit data is kept.
When this WOULD be correct
A question asking how to protect an Azure VM from a regional failure by deploying replicas across physically isolated locations would have availability zones as the correct answer.
- ✗
A scale set autoscale policy
Why it's wrong here
A scale set autoscale policy controls the number of virtual machine instances based on metrics like CPU or memory, enabling horizontal scaling to handle load changes. While autoscale activity itself is recorded in the activity log, the policy does not alter the retention duration of the log data; it only influences resource capacity, not audit data persistence.
When this WOULD be correct
When the question asks how to automatically adjust the number of VM instances in a scale set based on CPU load or other metrics, configuring an autoscale policy is the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Diagnostic settings for the activity logCorrect answer▾
Why this is correct
Diagnostic settings for the activity log are the correct mechanism because they allow you to route Azure activity log data to a Log Analytics workspace, storage account, or Event Hub. By default, activity logs are retained for only 90 days, but configuring diagnostic settings enables you to archive that data for years or stream it to analysis tools, satisfying long-term retention and compliance requirements.
✗A resource lock on the subscriptionWrong answer — click to see why▾
Why this is wrong here
A resource lock on the subscription prevents accidental deletion or modification of resources, but it does not extend the retention period of activity log data or enable its analysis.
★ When this WOULD be the correct answer
A resource lock would be correct in a scenario where you need to protect a critical subscription from accidental deletion or changes, such as when implementing governance controls for a production environment.
Why candidates choose this
Candidates may confuse resource locks with data retention controls, thinking that locking the subscription preserves all data indefinitely, or they may associate locks with long-term data protection.
✗An availability zoneWrong answer — click to see why▾
Why this is wrong here
Availability zones are physically separate datacenters within an Azure region used for high availability and disaster recovery, not for extending data retention or enabling analysis of activity logs.
★ When this WOULD be the correct answer
A question asking how to protect an Azure VM from a regional failure by deploying replicas across physically isolated locations would have availability zones as the correct answer.
Why candidates choose this
Candidates may confuse 'availability' with 'data availability' or think that zones provide some form of data retention or backup capability.
✗A scale set autoscale policyWrong answer — click to see why▾
Why this is wrong here
A scale set autoscale policy manages the number of VM instances in a virtual machine scale set based on demand, not the retention or analysis of Azure activity log data.
★ When this WOULD be the correct answer
When the question asks how to automatically adjust the number of VM instances in a scale set based on CPU load or other metrics, configuring an autoscale policy is the correct answer.
Why candidates choose this
Candidates may confuse 'scale' with 'retention period' or think that scaling settings affect data storage duration, or they may misassociate autoscale with log data management.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
Activity log
An activity log is a record of all operations performed on Azure resources, capturing who did what, when, and where, for auditing and troubleshooting purposes.
Key term
Log Analytics workspace
A Log Analytics workspace is a unique environment in Azure Monitor where log data from various sources is collected, stored, and queried for analysis and reporting.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.