Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to generate periodic reports of user sign-ins and audit activities for compliance. They want to store the logs for 1 year. Which Azure service should they use?

⚠ Common exam trap

Many exam-takers assume the Azure portal's retention slider for Entra ID logs can be extended beyond 30 days, but Microsoft intentionally limits it to 30 days to force the use of diagnostic settings and Log Analytics for long-term retention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Monitor Log Analytics workspace with Microsoft Entra ID diagnostic settings

Microsoft Entra ID sign-in and audit logs are retained for only 30 days by default. To store them for 1 year, you must route the logs via diagnostic settings to an Azure Monitor Log Analytics workspace, which allows configurable retention up to 2 years (or more with a commitment tier). This is the only native Azure service that supports long-term retention of Entra ID logs for compliance reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID sign-in logs and audit logs with retention set to 1 year in the Azure portal

    Why it's wrong here

    Native Microsoft Entra ID log retention is fixed by license: sign-in logs are kept for 7 days in Free and 30 days with P1/P2, while audit logs are kept for 30 days (or 90 days with P2). The Azure portal does not offer any way to set a one-year retention for these logs; to keep them longer, you must route them via diagnostic settings to an external destination such as a Log Analytics workspace.

  • ✓

    Azure Monitor Log Analytics workspace with Microsoft Entra ID diagnostic settings

    Why this is correct

    This is the correct answer because Microsoft Entra ID diagnostic settings can stream sign-in and audit logs directly to an Azure Monitor Log Analytics workspace. Log Analytics supports configurable retention periods up to 730 days (with options for longer-term archival), and its KQL query engine enables you to generate custom reports, dashboards, and alerts directly on the historical log data. This combined long-term storage and querying capability exactly satisfies the company's requirement to generate reports on sign-in and audit activity.

  • ✗

    Azure Storage account with lifecycle management

    Why it's wrong here

    Archiving to an Azure Storage account with lifecycle management is wrong for this scenario because lifecycle rules only manage blob tiers (hot, cool, archive) and deletion, not log querying or analysis. To generate reports from stored logs, you would need to build an ETL pipeline or export the data to a separate analytics service, adding complexity and latency. Storage is suitable for long-term compliance backups, but it is not a directly queryable, report-ready log analytics platform.

  • ✗

    Azure Event Hubs for streaming

    Why it's wrong here

    This option fails because Azure Event Hubs is a real-time streaming ingestion service, not a long-term log repository—it retains messages for a maximum of 7 days and by default only 1 day. It also lacks a query engine, so you cannot run KQL or other ad-hoc queries against historical sign-in and audit logs for reporting. Event Hubs is appropriate when you need to stream logs to a SIEM or real-time processing pipeline, not for meeting a one-year retention and reporting requirement.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.