Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company has an Azure subscription with a Log Analytics workspace. They need to ensure that all administrative operations performed on Azure resources are logged and retained for 90 days. The logs must be queryable using Kusto Query Language (KQL). What should you configure?

⚠ Common exam trap

The trap here is assuming that Azure Monitor metrics or Defender for Cloud can provide administrative operation logs; they serve different purposes and do not capture control-plane operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Activity Log with a diagnostic setting to send logs to the Log Analytics workspace.

The Azure Activity Log captures administrative operations at the subscription level. To retain and query these logs with KQL, you create a diagnostic setting that sends the Activity Log to a Log Analytics workspace. This provides long-term retention and powerful querying capabilities. Metrics, Defender for Cloud, and VM data collection rules do not capture administrative operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Activity Log with a diagnostic setting to send logs to the Log Analytics workspace.

    Why this is correct

    Azure Activity Log records administrative operations on resources. By creating a diagnostic setting to forward the Activity Log to a Log Analytics workspace, the logs become queryable using KQL and can be retained for 90 days (or more). This meets the requirement for logging administrative operations and querying them.

  • ✗

    Azure Monitor Logs with a data collection rule to collect Windows event logs from all VMs.

    Why it's wrong here

    Data collection rules are used to collect data from virtual machines, such as Windows event logs or performance counters. They do not collect Azure administrative operations. This approach would only cover VM logs, not the broader Azure resource operations required.

  • ✗

    Microsoft Defender for Cloud with continuous export to the Log Analytics workspace.

    Why it's wrong here

    Microsoft Defender for Cloud provides security alerts and recommendations, not administrative operation logs. Continuous export sends security data, not the Activity Log. It does not meet the requirement for logging all administrative operations on Azure resources.

  • ✗

    Azure Monitor metrics with a diagnostic setting to send metrics to the Log Analytics workspace.

    Why it's wrong here

    Azure Monitor metrics are numerical time-series data, not administrative operation logs. They do not capture who performed an operation or what changed. While metrics can be sent to a workspace, they do not fulfill the requirement for logging administrative operations.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.