A manufacturing enterprise is designing a monitoring and log routing architecture for its workloads deployed across the West US 3 and West Europe regions. The design must satisfy the following constraints:
- All application logs generated in the West Europe region must reside in Europe to comply with local data sovereignty regulations.
- Operations team members who only manage West US 3 resources must only be allowed to view logs originating from those West US 3 resources.
- High-priority security alerts must be streamed in near real-time to a third-party Security Information and Event Management (SIEM) system.
- The deployment and maintenance of diagnostic settings should be automated.
Which two of the following components should you include in the design? (Select two.)
- A Log Analytics workspace in West Europe and a Log Analytics workspace in West US 3Answer
- An Azure Event Hubs namespace to stream log data to the third-party SIEMAnswer
- CA single, centrally managed Log Analytics workspace in West US 3 to minimize workspace proliferation
- DAn Azure Policy definition configured with the Deny effect to enforce the deployment of diagnostic settings
- EDirect RBAC role assignments to individual operations team member accounts at the resource group level