AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company uses Microsoft Entra ID for identity management. You need to design a monitoring solution for sign-in logs to detect suspicious activity. Which TWO Azure services should you include in the design?
⚠ Common exam trap
The trap here is that candidates often select Azure Monitor or Log Analytics workspace alone, thinking they can detect suspicious activity, but they lack the built-in threat detection and analytics engines that are specific to security-focused services like Defender for Cloud Apps and Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps (Option B) is correct because it provides Cloud Access Security Broker (CASB) capabilities that analyze sign-in logs for anomalous behavior, such as impossible travel, suspicious IP addresses, and credential theft. It integrates with Microsoft Entra ID to detect and respond to risky sign-in events in real time, making it a core component for monitoring suspicious activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Monitor
Why it's wrong here
Azure Monitor is a telemetry and observability service that collects platform metrics, logs, and activity data from Azure resources, including Entra ID audit and sign-in logs if diagnostic settings are configured. However, it provides no native identity threat detection: it lacks prebuilt analytics rules, UEBA, or sign-in risk scoring to identify suspicious activity. At best you could author a custom KQL query, but that is a manual monitoring exercise, not an out-of-the-box security detection service.
- ✓
Microsoft Defender for Cloud Apps
Why this is correct
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that uses behavioral analytics and UEBA to profile each user's normal sign-in patterns. It can detect impossible-travel behavior, sign-ins from anonymous or risky IPs, and atypical locations or applications, then trigger alerts or conditional access policies based on the calculated risk. Because it is natively integrated with Microsoft Entra ID, it can directly monitor sign-in events and respond to suspicious activities, making it a strong fit for this identity-threat scenario.
- ✓
Microsoft Sentinel
Why this is correct
Microsoft Sentinel is a cloud-native SIEM with built-in UEBA and a rich library of analytics rules that can detect sign-in anomalies such as multiple failed attempts followed by success, sign-ins from known malicious IPs, or unusual authentication times and geographies. It ingests Entra ID sign-in logs and correlates them with other security data across the enterprise, giving analysts a centralized investigation and response workflow. This makes it a valid choice for identifying suspicious sign-in activities, particularly when you need cross-source threat hunting and automation.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is a comprehensive data governance, risk, and compliance platform, not an identity security service. It helps classify, protect, and monitor sensitive data across on-premises and cloud environments, such as enforcing data loss prevention policies or managing data lifecycle. While it may integrate with Entra ID for permission context, it does not analyze sign-in logs or apply anomaly-detection logic to identity events, so it cannot detect suspicious sign-in activities.
- ✗
Log Analytics workspace
Why it's wrong here
A Log Analytics workspace is the underlying data store and query engine used by Azure Monitor and Microsoft Sentinel, but on its own it is passive—it only receives, retains, and allows querying of log data. It offers KQL-based search and storage, yet no built-in threat detection rules, UEBA, or sign-in risk scoring. To detect suspicious sign-in activities, you would need to layer Sentinel or Defender for Cloud Apps on top, so the workspace alone is not a detection solution.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.