Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company requires that all administrative actions in Azure subscriptions be logged and retained for seven years. Which service should you use to collect and store these logs?

⚠ Common exam trap

Test-takers frequently confuse the Azure Activity Log (control-plane) with Microsoft Entra ID audit logs (identity-plane), or mistakenly think Azure Monitor Metrics can store long-term administrative logs instead of numerical performance data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Activity Log

The Azure Activity Log (now part of Azure Monitor) records all control-plane operations (create, update, delete) on Azure resources and can be retained for up to seven years by configuring a diagnostic setting to stream the logs to a Log Analytics workspace or Azure Storage. This meets the requirement for logging and long-term retention of administrative actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Monitor Metrics

    Why it's wrong here

    Azure Monitor Metrics stores numeric performance counters and time-series data (such as CPU usage, memory consumption, and disk I/O) emitted by Azure resources. It contains no information about the identity of a user, the specific administrative action performed, or the timestamp of management-plane operations like creating or deleting a resource. Therefore, it cannot be used to audit administrative actions, even though it may be valuable for detecting performance anomalies.

  • ✗

    Azure Resource Health

    Why it's wrong here

    Azure Resource Health continuously assesses whether an Azure resource is currently available and provides a status of either 'Available,' 'Unavailable,' or 'Unknown,' along with a history of platform and non-platform events that affected availability. It reports on service health and outages, not on who executed a management operation such as stopping a virtual machine or updating a firewall rule. Therefore, it cannot provide an audit trail of administrative actions, as it is designed for monitoring live health rather than recording operation logs.

  • ✓

    Azure Activity Log

    Why this is correct

    The Azure Activity Log is a subscription-level audit log that records every control-plane operation (create, update, delete, and write) on Azure resources, including the actor (who initiated the action), the timestamp, the operation name, and the status. It captures administrative actions such as starting or stopping a virtual machine, modifying a network security group, or assigning a policy, and can be retained for up to 7 years when exported to a storage account or Log Analytics workspace. This makes it the correct source for answering who did what, when, and where in your Azure environment.

  • ✗

    Microsoft Entra ID audit logs

    Why it's wrong here

    Microsoft Entra ID audit logs record identity-related activities in the directory, such as user sign-ins, password resets, group membership changes, and application registrations. They do not capture Azure resource control-plane operations, like creating a virtual network or restarting a database server, because those are management operations on Azure resources, not on directory objects. Thus, while Entra ID audit logs are essential for identity governance and security investigations, they are not a substitute for the Azure Activity Log when auditing administrative actions on resources.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.