Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company operates in a highly regulated industry and must retain all sign-in logs for 7 years. The logs must be immutable and cannot be modified or deleted by administrators. You need to design a monitoring solution that stores sign-in logs in a cost-effective manner while meeting compliance requirements. The solution should also allow for real-time analysis of sign-in activity. What should you include in the design?

⚠ Common exam trap

It's easy for candidates to assume Log Analytics retention alone suffices for compliance, but Log Analytics does not provide immutable storage, and Azure Policy cannot prevent data modification within the workspace; the correct approach requires separate immutable archival in Azure Storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stream sign-in logs to Log Analytics for real-time analysis and simultaneously archive them to an Azure Storage account with immutable blob policy (WORM).

It meets both compliance and real-time analysis requirements. Streaming sign-in logs to Log Analytics enables real-time monitoring and querying, while simultaneously archiving them to an Azure Storage account with an immutable blob policy (WORM) ensures the logs cannot be modified or deleted for the required 7-year retention period. This combination provides cost-effective long-term storage (Azure Blob is cheaper than Log Analytics for long-term retention) and satisfies regulatory immutability mandates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Stream sign-in logs to Log Analytics for real-time analysis and simultaneously archive them to an Azure Storage account with immutable blob policy (WORM).

    Why this is correct

    Streaming sign-in logs to Log Analytics enables near real-time querying and alerting for security operations, satisfying the need for fast analysis. Simultaneously archiving the same logs to an Azure Storage account with immutable blob policy (WORM) ensures that the archived copies are both write-once-read-many and tamper-proof for the mandatory retention period. This dual-destination pattern is explicitly supported by Azure diagnostic settings, making it the correct approach for regulated industries that require both investigative access and compliance-grade immutability.

  • ✗

    Stream sign-in logs to Azure Event Hubs and then to cold storage in Azure Blob with lifecycle management.

    Why it's wrong here

    Azure Event Hubs is designed for high-throughput real-time data ingestion and downstream processing, not for long-term compliance-grade storage. Routing logs to cold Blob storage with lifecycle management only automates tiering and eventual deletion based on age or other rules; it does not provide any immutability guarantees. A user with storage account write access could still modify or delete blobs, and lifecycle policies cannot enforce WORM protections. Thus, this approach supports cost-effective storage but fails the regulatory requirement for tamper-proof evidence.

  • ✗

    Stream sign-in logs to Log Analytics workspace with 7-year retention and use Azure Policy to restrict deletion.

    Why it's wrong here

    While a Log Analytics workspace can be configured with extended retention up to years, Azure Policy merely evaluates and enforces resource configuration rules; it cannot make the actual log data immutable. Policies restrict what actions administrators can take on resources, but they do not prevent a compromised or malicious user with Contributor rights from issuing direct data modification or purge commands. Even with 7-year retention, Log Analytics data can be altered or removed through supported APIs without a WORM layer. Therefore, using Azure Policy alone gives a false sense of compliance because data integrity is not cryptographically protected.

  • ✗

    Use Azure Data Explorer to store logs for 7 years and configure a purge policy to prevent deletion.

    Why it's wrong here

    Azure Data Explorer (ADX) is optimized for interactive analytics over large volumes of time-series and event data, and its purge policies are specifically designed to permanently delete data for privacy or regulatory erasure requirements, not to prevent deletion. Configuring a purge policy would actually enable automatic removal of logs, which is the opposite of immutable retention. Additionally, ADX storage does not offer native WORM or legal hold capabilities, so even without purge, data could be overwritten or deleted by authorized operations. This option is fundamentally misaligned with the goal of preserving logs for 7 years without alteration.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.