AZ-305 Design infrastructure solutions Practice Question
You need to design a monitoring solution for a set of Azure virtual machines running a business-critical application. The solution must provide centralized log management, enable real-time analysis of security events, and support custom alerts for anomalous behavior. Which Azure service should you use?
⚠ Common exam trap
Test-takers frequently confuse Azure Monitor (a general monitoring tool) with Microsoft Sentinel (a dedicated SIEM), failing to recognize that the question's emphasis on 'security events' and 'anomalous behavior' points to a security-specific solution, not just log aggregation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel
Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that provides centralized log management, real-time security event analysis, and built-in support for custom analytics rules to detect anomalous behavior. Unlike Azure Monitor or Log Analytics, Sentinel is specifically designed for security-focused monitoring and can ingest logs from multiple sources, including Azure VMs, and use machine learning to identify threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Log Analytics
Why it's wrong here
Azure Log Analytics is a query engine and data store within Azure Monitor that ingests and analyzes logs, but it is not a full SIEM because it lacks security-specific capabilities such as incident management, threat intelligence correlation, entity behavior analytics, and automated response workflows. Although you can write KQL queries to detect suspicious activity, you must build all correlation logic manually and manage every alert lifecycle yourself, whereas a SIEM like Microsoft Sentinel provides those features natively on top of the same Log Analytics workspace. Thus, Log Analytics alone is only a component of a SIEM, not a complete monitoring and security analysis solution.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that generates security recommendations, assesses regulatory compliance, and detects threats on Azure workloads, but it is not designed for centralized log management or custom security event analysis. It pulls security findings into your environment, and it can stream those alerts to Sentinel, but it does not give you a unified SIEM interface to query arbitrary logs from all sources, build custom detection rules, or manage incident response across your entire hybrid estate. Therefore, Defender for Cloud answers 'how secure is my posture?' rather than 'what did these logs mean?' and is not a replacement for Sentinel.
- ✗
Azure Monitor
Why it's wrong here
Azure Monitor provides broad observability—collecting platform metrics, resource logs, and application telemetry and enabling dashboards, alerts, and workbook visualizations—but it is not a SIEM because it lacks the forensic analysis, correlation of security signals, entity and user-behavior analytics, and built-in threat response playbooks expected from a security information and event management platform. Azure Monitor's alerts are operational or based on simple queries, and it does not integrate with external threat intelligence feeds to enrich security events or automatically open incident tracks. It is the infrastructure under a SIEM, not the SIEM itself, which is why you would need Sentinel to perform security event analysis and custom alerting beyond basic monitoring.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a cloud-native, scalable SIEM (Security Information and Event Management) solution that builds on Azure Log Analytics to provide centralized log management, analysis, and custom alerting across your entire digital estate. It ingests data from hundreds of sources—Microsoft services, third-party firewalls, cloud workloads, and on-premises systems—then uses KQL queries, analytics rules, and machine learning to detect threats, and its SOAR capabilities automate incident response. Sentinel also offers entity behavior analytics and integrated threat intelligence, making it the only option listed that meets the stated requirement for a monitoring solution that includes log management, security analysis, and custom alerts.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.