AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company operates in a highly regulated industry and must retain all sign-in logs for 7 years. The logs must be immutable and cannot be modified or deleted by administrators. You need to design a monitoring solution that stores sign-in logs in a cost-effective manner while meeting compliance requirements. The solution should also allow for real-time analysis of sign-in activity. What should you include in the design?
⚠ Common exam trap
It's easy for candidates to assume Log Analytics retention alone suffices for compliance, but Log Analytics does not provide immutable storage, and Azure Policy cannot prevent data modification within the workspace; the correct approach requires separate immutable archival in Azure Storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stream sign-in logs to Log Analytics for real-time analysis and simultaneously archive them to an Azure Storage account with immutable blob policy (WORM).
It meets both compliance and real-time analysis requirements. Streaming sign-in logs to Log Analytics enables real-time monitoring and querying, while simultaneously archiving them to an Azure Storage account with an immutable blob policy (WORM) ensures the logs cannot be modified or deleted for the required 7-year retention period. This combination provides cost-effective long-term storage (Azure Blob is cheaper than Log Analytics for long-term retention) and satisfies regulatory immutability mandates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Stream sign-in logs to Log Analytics for real-time analysis and simultaneously archive them to an Azure Storage account with immutable blob policy (WORM).
Why this is correct
Streaming sign-in logs to Log Analytics enables near real-time querying and alerting for security operations, satisfying the need for fast analysis. Simultaneously archiving the same logs to an Azure Storage account with immutable blob policy (WORM) ensures that the archived copies are both write-once-read-many and tamper-proof for the mandatory retention period. This dual-destination pattern is explicitly supported by Azure diagnostic settings, making it the correct approach for regulated industries that require both investigative access and compliance-grade immutability.
- ✗
Stream sign-in logs to Azure Event Hubs and then to cold storage in Azure Blob with lifecycle management.
Why it's wrong here
Azure Event Hubs is designed for high-throughput real-time data ingestion and downstream processing, not for long-term compliance-grade storage. Routing logs to cold Blob storage with lifecycle management only automates tiering and eventual deletion based on age or other rules; it does not provide any immutability guarantees. A user with storage account write access could still modify or delete blobs, and lifecycle policies cannot enforce WORM protections. Thus, this approach supports cost-effective storage but fails the regulatory requirement for tamper-proof evidence.
- ✗
Stream sign-in logs to Log Analytics workspace with 7-year retention and use Azure Policy to restrict deletion.
Why it's wrong here
While a Log Analytics workspace can be configured with extended retention up to years, Azure Policy merely evaluates and enforces resource configuration rules; it cannot make the actual log data immutable. Policies restrict what actions administrators can take on resources, but they do not prevent a compromised or malicious user with Contributor rights from issuing direct data modification or purge commands. Even with 7-year retention, Log Analytics data can be altered or removed through supported APIs without a WORM layer. Therefore, using Azure Policy alone gives a false sense of compliance because data integrity is not cryptographically protected.
- ✗
Use Azure Data Explorer to store logs for 7 years and configure a purge policy to prevent deletion.
Why it's wrong here
Azure Data Explorer (ADX) is optimized for interactive analytics over large volumes of time-series and event data, and its purge policies are specifically designed to permanently delete data for privacy or regulatory erasure requirements, not to prevent deletion. Configuring a purge policy would actually enable automatic removal of logs, which is the opposite of immutable retention. Additionally, ADX storage does not offer native WORM or legal hold capabilities, so even without purge, data could be overwritten or deleted by authorized operations. This option is fundamentally misaligned with the goal of preserving logs for 7 years without alteration.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.