AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. You need to ensure that all Azure subscriptions are covered by a single continuous export configuration that sends security alerts to a Log Analytics workspace. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure continuous export at the management group level.
Continuous export can be configured at the subscription level or management group scope. By configuring it at the management group level, all subscriptions under that management group inherit the export settings. This provides a single configuration point.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Azure Policy to deploy continuous export settings to all subscriptions.
Why it's wrong here
Azure Policy can enforce settings, but continuous export is a configuration setting, not a policy effect. However, you can use policy to deploy a 'DeployIfNotExists' to configure export, but the question asks for a single configuration, not a policy.
- ✓
Configure continuous export at the management group level.
Why this is correct
Configuring continuous export at the management group level is the correct single configuration point. In Microsoft Defender for Cloud, you can define the export settings (target Log Analytics workspace or Event Hub, and the data types such as alerts and recommendations) at a management group scope, and those settings are inherited by every subscription under that group. This ensures a consistent, centrally managed configuration without needing to touch individual subscriptions, and any new subscription added to the group automatically receives the same export settings.
- ✗
Create an Azure Automation runbook to export settings to all subscriptions.
Why it's wrong here
Creating an Azure Automation runbook to export settings is a procedural workaround, not a native configuration. A runbook would need to script a loop that enumerates all subscriptions and calls the Defender for Cloud REST API or PowerShell cmdlets to set continuous export on each one, introducing dependencies on credentials, error handling, and a scheduler. Even then, it only configures subscriptions at the moment the runbook runs, so it does not provide ongoing inheritance or a single persistent configuration point—making it more complex and error-prone than the management group approach.
- ✗
Configure continuous export in each subscription individually.
Why it's wrong here
Configuring continuous export in each subscription individually is the opposite of a single configuration. It requires manually repeating the same steps across every existing subscription and then repeating them again for any subscription created later, which inevitably leads to configuration drift and compliance gaps. Because these settings are stored per subscription rather than inherited, you lose central visibility and must invest in additional audit or remediation tooling to enforce consistency—making this approach neither efficient nor scalable.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.