Courseiva

AZ-305 Design infrastructure solutions Practice Question

You are designing a solution to monitor a hybrid environment consisting of Azure VMs and on-premises servers. The solution must provide centralized log analytics, security threat detection, and the ability to run custom queries across all logs. Which TWO Azure services should you include? (Choose two.)

⚠ Common exam trap

Candidates often confuse Azure Monitor Agent (a data collector) with Azure Monitor itself, mistakenly thinking the agent alone provides analytics and querying, when in fact it only forwards data to a Log Analytics workspace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Log Analytics workspace

A Log Analytics workspace is the central repository in Azure that ingests and stores log data from various sources, including Azure VMs and on-premises servers. It enables you to run custom Kusto Query Language (KQL) queries across all collected logs, which directly satisfies the requirement for centralized log analytics and custom querying.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Monitor Agent

    Why it's wrong here

    Azure Monitor Agent is a data collection agent, not an analytics service. It gathers telemetry from the OS and workloads on VMs, including hybrid servers, and forwards it to a Log Analytics workspace. By itself it provides no querying, alerting, or visualization; those capabilities reside in the workspace. Therefore choosing it as the answer confuses ingestion with analysis.

  • ✓

    Azure Log Analytics workspace

    Why this is correct

    Azure Log Analytics workspace is the central data repository in Azure Monitor that receives logs and metrics from Azure and non-Azure sources, including hybrid machines via the Azure Monitor Agent. It provides the KQL query language to analyze, correlate, and visualize data, and serves as the foundation for alerts, workbooks, and dashboards. This makes it the correct choice when the requirement is to monitor and analyze a hybrid environment.

  • ✓

    Microsoft Sentinel

    Why this is correct

    Microsoft Sentinel is a native cloud SIEM and SOAR solution built on top of a Log Analytics workspace. It adds advanced security threat detection, incident management, hunting, and automation capabilities across on-premises and cloud workloads. Sentinel is a correct choice when the monitoring design emphasizes security analytics, but it still relies on a Log Analytics workspace for data storage and querying.

  • ✗

    Azure Arc

    Why it's wrong here

    Azure Arc is a hybrid management and governance service that extends Azure Resource Manager to on-premises and multi-cloud servers. It enables policy assignment, inventory tracking, and role-based access control, but it does not ingest log data or provide analytical queries. For log monitoring, Arc works alongside the Azure Monitor Agent but is not a substitute for a centralized Log Analytics workspace.

  • ✗

    Azure Update Manager

    Why it's wrong here

    Azure Update Manager is a service for managing OS patching and update compliance across hybrid and multi-cloud VMs. It tracks patch installation status and schedules updates but does not collect or query arbitrary log data for general monitoring. Monitoring a hybrid environment's overall health requires a telemetry destination and query engine, not patch orchestration.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.