Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company has multiple Azure subscriptions. You need to ensure that all security-related logs from Azure resources are centralized in a single Log Analytics workspace for analysis. Which Azure service should you use to collect and route these logs?

⚠ Common exam trap

Watch out — candidates often confuse Azure Policy with Azure Monitor or Sentinel, thinking that monitoring or SIEM tools handle log routing, when in fact Azure Policy is the governance tool that enforces the configuration to centralize logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy

Azure Policy is correct because it can enforce the deployment of a diagnostic setting on all Azure resources, automatically routing security-related logs (such as Activity Logs, resource logs, and audit logs) to a single Log Analytics workspace. This ensures centralized collection and analysis without manual configuration per resource, meeting the requirement for a governance-driven approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Monitor

    Why it's wrong here

    Azure Monitor is the platform service that collects, analyzes, and acts on telemetry after logs are actually flowing; it does not have a policy engine that can enforce or remediate diagnostic settings across multiple subscriptions. You can use Azure Monitor workbooks and log queries to view data, but it cannot mandate that each resource is configured to export logs to a central workspace. Therefore, while Azure Monitor is the destination and analysis layer, it is not the mechanism that enforces centralized log collection.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR solution that ingests security events from sources such as a Log Analytics workspace and applies detection, hunting, and automation rules. It depends on logs already being centralized; it has no native way to deploy the underlying diagnostic settings across every subscription or resource type. Selecting Sentinel would not solve the requirement to route logs consistently, and its value only begins after the needed log collection mechanism has already been put in place.

  • ✓

    Azure Policy

    Why this is correct

    Azure Policy provides a governance control plane that can evaluate and enforce resource configuration at scale, and the built-in 'Deploy Diagnostic Settings to Log Analytics Workspace' initiative or a custom DeployIfNotExists policy will automatically create and remediate diagnostic settings on each supported resource. You can assign that initiative to a management group containing multiple subscriptions, and policy remediation tasks will continuously bring non-compliant resources back into compliance. This makes Azure Policy the correct tool because it enforces, rather than merely observes or analyzes, the routing of resource logs to a central workspace.

  • ✗

    Azure Event Hubs

    Why it's wrong here

    Azure Event Hubs is a high-throughput real-time streaming ingestion service intended to feed downstream consumers, such as a SIEM or custom analytics pipeline, with near-zero latency. Although diagnostic settings can be configured to stream platform logs to an Event Hubs namespace, Event Hubs does not provide durable, queryable central log storage and cannot enforce the diagnostic configuration on resources across subscriptions. Choosing Event Hubs would solve an ingestion or streaming need, but not the centralized retention, query, and governance requirement in the scenario.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.