Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company uses Microsoft Entra ID for identity management. You need to design a monitoring solution for sign-in logs to detect suspicious activity. Which TWO Azure services should you include in the design?

⚠ Common exam trap

The trap here is that candidates often select Azure Monitor or Log Analytics workspace alone, thinking they can detect suspicious activity, but they lack the built-in threat detection and analytics engines that are specific to security-focused services like Defender for Cloud Apps and Sentinel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps (Option B) is correct because it provides Cloud Access Security Broker (CASB) capabilities that analyze sign-in logs for anomalous behavior, such as impossible travel, suspicious IP addresses, and credential theft. It integrates with Microsoft Entra ID to detect and respond to risky sign-in events in real time, making it a core component for monitoring suspicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Monitor

    Why it's wrong here

    Azure Monitor is a telemetry and observability service that collects platform metrics, logs, and activity data from Azure resources, including Entra ID audit and sign-in logs if diagnostic settings are configured. However, it provides no native identity threat detection: it lacks prebuilt analytics rules, UEBA, or sign-in risk scoring to identify suspicious activity. At best you could author a custom KQL query, but that is a manual monitoring exercise, not an out-of-the-box security detection service.

  • ✓

    Microsoft Defender for Cloud Apps

    Why this is correct

    Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that uses behavioral analytics and UEBA to profile each user's normal sign-in patterns. It can detect impossible-travel behavior, sign-ins from anonymous or risky IPs, and atypical locations or applications, then trigger alerts or conditional access policies based on the calculated risk. Because it is natively integrated with Microsoft Entra ID, it can directly monitor sign-in events and respond to suspicious activities, making it a strong fit for this identity-threat scenario.

  • ✓

    Microsoft Sentinel

    Why this is correct

    Microsoft Sentinel is a cloud-native SIEM with built-in UEBA and a rich library of analytics rules that can detect sign-in anomalies such as multiple failed attempts followed by success, sign-ins from known malicious IPs, or unusual authentication times and geographies. It ingests Entra ID sign-in logs and correlates them with other security data across the enterprise, giving analysts a centralized investigation and response workflow. This makes it a valid choice for identifying suspicious sign-in activities, particularly when you need cross-source threat hunting and automation.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview is a comprehensive data governance, risk, and compliance platform, not an identity security service. It helps classify, protect, and monitor sensitive data across on-premises and cloud environments, such as enforcing data loss prevention policies or managing data lifecycle. While it may integrate with Entra ID for permission context, it does not analyze sign-in logs or apply anomaly-detection logic to identity events, so it cannot detect suspicious sign-in activities.

  • ✗

    Log Analytics workspace

    Why it's wrong here

    A Log Analytics workspace is the underlying data store and query engine used by Azure Monitor and Microsoft Sentinel, but on its own it is passive—it only receives, retains, and allows querying of log data. It offers KQL-based search and storage, yet no built-in threat detection rules, UEBA, or sign-in risk scoring. To detect suspicious sign-in activities, you would need to layer Sentinel or Defender for Cloud Apps on top, so the workspace alone is not a detection solution.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.