All practice questions

1198 questions

Question 741Question

An enterprise is designing a centralized monitoring and log routing architecture for its Azure environment. The architecture must accommodate various auditing, security, and networking logs while satisfying constraints around operational cost, real-time analysis, administrative access control, and long-term retention.

Match each log routing requirement scenario on the left with the most appropriate Azure destination or architectural configuration on the right.

Click a left item, then click its matching right item

Items

Virtual Network flow logs requiring flow visualization, traffic patterns analysis, and a 7-year data retention compliance policy.
Near-real-time streaming of Microsoft Entra ID security logs to a third-party, non-Azure Security Information and Event Management (SIEM) system.
Diagnostic logs from Azure Key Vaults and App Services across multiple subscriptions that require joint querying while keeping access restricted based on resource-level permissions.
Archiving of subscription-wide administrative operation events (write, delete, and action actions) for low-cost compliance storage over several years.

Matches

Show answer & explanation

Answer

The correct matches pair: (1) Virtual Network flow logs requiring Traffic Analytics and 7-year retention with a Storage Account target for Network Watcher flow logs integrated with Traffic Analytics in a Log Analytics Workspace; (2) Microsoft Entra ID log streaming to a third-party SIEM with an Azure Event Hubs namespace; (3) Centralized resource diagnostic querying with resource-level permissions to a centralized Log Analytics Workspace using resource-context access control; (4) Low-cost Activity Log archiving with a dedicated Storage Account with lifecycle management rules.
The correct matches map each log source and constraint to the appropriate architectural endpoint: Event Hubs for external SIEM streaming, resource-context Log Analytics Workspaces for decentralized querying with RBAC controls, Network Watcher flow logs to Storage plus Traffic Analytics for flow analysis, and Storage Accounts with lifecycle rules for long-term Activity Log archiving.

Step-by-Step Solution

1
Identify the destination for third-party SIEM integration.
Azure Event Hubs is the standard ingress/egress mechanism for streaming Azure platform logs to external partner SIEMs in real-time.
Log Analytics and Storage Accounts do not natively push logs to external SIEMs in near-real-time without intermediary compute or custom agents.
2
Analyze administrative boundary requirements for diagnostic logs.
A centralized Log Analytics Workspace configured with resource-context RBAC allows users to query logs for resources they own without having access to the entire workspace.
This satisfies the requirement for joint querying across subscriptions while respecting resource-level administrative access control.
3
Determine the optimal routing for VNet flow analysis and long-term retention.
Network Watcher flow logs must be written to a Storage Account first, which can then be ingested by a Log Analytics Workspace with Traffic Analytics enabled for visualization.
The Storage Account handles the low-cost raw data retention (7 years), while Traffic Analytics handles the operational flow analysis.
4
Select the storage target for subscription-level Activity Log archiving.
Azure Storage Accounts with lifecycle management policies are the most cost-effective target for long-term archiving of Activity Logs.
Activity Logs represent subscription-wide control-plane events, and storing them in Log Analytics for long periods would incur unnecessarily high costs.

Key Concept

Designing Azure Monitor diagnostic log routing architecture and access control models to meet compliance, security, and administrative isolation requirements.
Question 742Question

A cloud architecture team is implementing a monitoring strategy for a set of new Azure workloads. The team needs to configure diagnostic settings to satisfy two compliance conditions:

1. Stream resource logs immediately to an external Security Information and Event Management (SIEM) platform.
2. Retain all log data for five years in a secure archive at the lowest possible cost.

Which two Azure destinations should be selected in the diagnostic settings to meet these requirements? (Select TWO)

Select all that apply

Show answer & explanation

Answer: An Azure Event Hubs namespace and event hub; An Azure Storage account

Answer

An Azure Event Hubs namespace and event hub, and an Azure Storage account
To satisfy both requirements, you must route diagnostic logs to two distinct destinations in the diagnostic settings. First, sending logs to an Azure Event Hub allows for near-real-time streaming to external SIEM systems. Second, routing logs to an Azure Storage account provides a low-cost, long-term storage solution for compliance auditing.

Step-by-Step Solution

1
Analyze the real-time SIEM integration requirement.
Identify that Azure Event Hubs is the correct integration point for streaming data to external, third-party SIEM platforms.
Event Hubs provides near-real-time message ingestion, which is required for external SIEM connectivity.
2
Analyze the long-term, low-cost storage requirement.
Identify that an Azure Storage account offers the lowest-cost option for log data retention over a five-year period.
Compared to Log Analytics, Storage account retention costs are significantly lower for cold, archived logs.
3
Evaluate and eliminate incorrect architectural configurations.
Discard options suggesting Deny policies for remediation, individual RBAC assignments, and centralized workspaces that bypass residency/cost constraints.
These alternatives violate operational, governance, and cost efficiency guidelines.

Key Concept

Log routing destinations in Azure Monitor diagnostic settings
Question 743Question

You are designing a log routing and monitoring strategy for an Azure infrastructure solution. Match each Azure destination to its primary use case.

Click a left item, then click its matching right item

Items

Azure Storage Account
Azure Event Hubs
Azure Monitor Log Analytics workspace

Matches

Show answer & explanation

Answer

Azure Storage Account matches with cost-effective, long-term archival and data retention for compliance audits. Azure Event Hubs matches with real-time ingestion and streaming of telemetry to third-party SIEM platforms. Azure Monitor Log Analytics workspace matches with centralized interactive querying, visualization, and metric alerting.
Each Azure log destination serves a distinct architectural purpose: Storage Accounts provide high-capacity, low-cost long-term retention; Event Hubs enable real-time ingestion and external data forwarding; Log Analytics workspaces enable immediate, rich analysis and alerting.

Step-by-Step Solution

1
Identify the destination engineered for maximum cost efficiency over long storage durations.
Azure Storage Account matches with long-term archival and compliance retention.
Azure Blob Storage tiers (cool/cold/archive) offer very low storage costs for logs that do not need to be searched frequently.
2
Identify the destination designed for high-throughput, low-latency log streaming to external integrations.
Azure Event Hubs matches with real-time streaming to third-party SIEMs.
Azure Event Hubs operates as a message broker capable of streaming telemetry directly to external endpoints like Splunk or QRadar.
3
Identify the destination built for data analysis, diagnostic queries, and performance dashboards.
Azure Monitor Log Analytics workspace matches with interactive querying, visualization, and alerting.
Log Analytics supports Kusto Query Language (KQL) search, visual charts, and integration with Azure Monitor Alert rules.

Key Concept

Log routing paths and destinations within Azure Monitor diagnostic settings.
Estimated Time:1m 0s
Question 744Question

An organization wants to restrict the deployment of specific virtual machine sizes in a test resource group. If an administrator attempts to deploy a virtual machine with a size that is not on the allowed list, the deployment must be immediately blocked. Which Azure Policy effect should you recommend to meet this requirement?

Show answer & explanation

Answer: Deny

Answer

Deny
The correct option is Deny. The Deny effect is used to block resource requests that do not comply with the policy definition, preventing the deployment from succeeding in the first place.

Step-by-Step Solution

1
Analyze the compliance requirement to determine the desired outcome upon finding a non-compliant deployment attempt.
The requirement states that the deployment of unauthorized virtual machine sizes must be immediately blocked.
Identifying the enforcement action (blocking vs. auditing or remediating) is the key step to selecting the correct policy effect.
2
Evaluate the available Azure Policy effects against the blocking requirement.
The Deny effect prevents the creation or update of resources that do not match the policy definition, whereas Audit only logs the event, and DeployIfNotExists or Modify attempt remediation/alteration.
Selecting the policy effect that aligns with immediate prevention ensures cost controls are enforced at deployment time.

Key Concept

Azure Policy Effects for Compliance Enforcement
Estimated Time:45s
Question 745Question

You are designing a centralized monitoring and log routing architecture for an enterprise with multiple Azure subscriptions. You need to map each corporate log management requirement to its optimal Azure service architecture. Each configuration must satisfy the constraints while minimizing administrative overhead and cost.

Match each operational requirement on the left to the most appropriate Azure architecture design on the right.

Click a left item, then click its matching right item

Items

Azure Activity logs from all subscriptions must be retained for 77 years for regulatory audit compliance. The logs are rarely accessed, and minimizing long-term storage costs is the primary concern.
Resource diagnostic logs must be processed in near real-time by a third-party SIEM system located on-premises. You must avoid duplicate data storage charges within Azure.
Virtual machine security event logs from all environments must be ingested for analysis with Microsoft Sentinel. Non-security administrators must be blocked from viewing these security logs.
High-volume web application console logs from resources in multiple regions are needed for KQL-based troubleshooting for up to 1010 days. You must minimize ingestion costs and avoid cross-region network egress charges.

Matches

Show answer & explanation

Answer

The requirement for 77-year Activity log storage matches the centralized Storage account with Archive tier lifecycle. The requirement for real-time SIEM streaming matches the Event Hubs direct routing. The VM security logs requirement matches the dedicated workspace with Sentinel and workspace-context RBAC. The regional developer debugging requirement matches regional workspaces configured with the Basic Logs plan.
The correct matches align Azure monitoring features to business constraints: Storage Archive tier for compliance log retention; Event Hubs for real-time external SIEM streaming; dedicated Sentinel workspace with workspace-context RBAC for SecOps isolation; and regional workspaces with Basic Logs tables for low-cost, egress-free developer debugging.

Step-by-Step Solution

1
Evaluate long-term audit logs path.
Identify that Azure Storage Archive tier offers the lowest cost per gigabyte for 77-year compliance storage of rarely accessed Activity logs.
Log Analytics and Event Hubs are optimized for querying and streaming, making them cost-prohibitive for inactive multi-year archival storage.
2
Analyze near real-time SIEM streaming.
Route the logs to Azure Event Hubs as a diagnostic setting destination without routing them to Log Analytics first.
This configuration satisfies the real-time consumption requirement of the on-premises SIEM while avoiding storage and double-ingestion fees in Azure.
3
Address central security logging with Sentinel and access control.
Design a dedicated centralized Log Analytics workspace with Sentinel and apply workspace-context RBAC.
Microsoft Sentinel operates at the workspace level. Using a dedicated workspace and workspace-context RBAC ensures security data is isolated from resource administrators who otherwise could view resource-context logs.
4
Optimize developer troubleshooting logs across regions.
Use regional Log Analytics workspaces and configure the target log tables to the Basic Logs plan.
Regional workspaces eliminate cross-region egress data transfer charges for log ingestion, and the Basic Logs plan dramatically reduces ingestion costs for high-volume logs that are only needed for short-term debugging.

Key Concept

Designing cost-effective, secure, and performant log routing configurations in Azure using Storage, Event Hubs, and Log Analytics plans.
Question 746Question

A financial services firm designs an Azure Landing Zone. The Azure hierarchy contains a management group named Production-MG, which contains 15 subscriptions.

You need to design a governance solution for Azure Key Vault instances deployed across all subscriptions in Production-MG. The solution must meet the following requirements:
- Ensure all Key Vaults automatically send audit logs to a central Log Analytics workspace.
- Allow developers to provision Key Vaults immediately, even if they do not define diagnostic settings in their templates.
- Prevent compliance validation and logging for two specific subscriptions within Production-MG that host isolated sandboxes.
- Minimize administrative overhead.

Which of the following policy designs should you recommend?

Show answer & explanation

Answer: A policy definition with the DeployIfNotExists effect assigned to the Production-MG management group, with the two sandbox subscriptions specified in the notScopes property of the assignment.

Answer

A policy definition with the DeployIfNotExists effect assigned to the Production-MG management group, with the two sandbox subscriptions specified in the notScopes property of the assignment.
The correct design uses the DeployIfNotExists effect, which evaluates compliance after a resource is created and automatically deploys the diagnostic settings child resource if it is missing. This prevents deployments from being blocked. Assigning the policy to the Production-MG management group with the two sandbox subscriptions in the notScopes exclusion property ensures governance across all required subscriptions with minimal administrative effort.

Step-by-Step Solution

1
Determine the required policy effect for automatic remediation and unblocked deployment.
The DeployIfNotExists effect is selected.
DeployIfNotExists allows resources to be deployed immediately and automatically remediates compliance by deploying missing child resources (diagnostic settings) afterwards. The Deny effect would block deployments, while the Modify effect is restricted to editing parent resource properties/tags.
2
Select the correct assignment scope and exemption strategy to minimize administrative overhead.
Assign the policy at the Production-MG management group level and specify the two sandbox subscriptions in the notScopes property.
Assigning at the management group level ensures policy inheritance across all 15 subscriptions. Using the notScopes property excludes the sandbox subscriptions from compliance evaluation at the assignment level, eliminating the need to manage 13 individual subscription-level assignments.

Key Concept

Azure Policy effects (DeployIfNotExists vs. Deny/Modify) and assignment scopes with inheritance exclusions (notScopes).
Question 747Question

An organization has two departments, Finance and HR, that run workloads in separate Azure subscriptions. Regulatory compliance requires that HR administrators must not have access to Finance security logs, and Finance administrators must not have access to HR security logs. You need to design an Azure Monitor log routing architecture that enforces this boundary. Which architecture should you recommend?

Show answer & explanation

Answer: Create separate Log Analytics workspaces for the Finance and HR subscriptions, and route the diagnostic logs of each subscription to its respective workspace.

Answer

Create separate Log Analytics workspaces for the Finance and HR subscriptions, and route the diagnostic logs of each subscription to its respective workspace.
Creating separate Log Analytics workspaces for the Finance and HR subscriptions ensures that log data is stored in isolated repositories. This satisfies the strict regulatory compliance requirement by preventing cross-department access to security logs, as workspace-level permissions can be restricted to authorized personnel of each department.

Step-by-Step Solution

1
Identify the data isolation and compliance requirements between the two departments.
HR and Finance departments require strict administrative isolation of security logs, meaning neither can access the other's logs.
This establishes the core design boundary where separate administrative access controls are mandatory.
2
Determine the appropriate workspace boundary in Azure Monitor.
Since Log Analytics workspaces serve as the primary administrative and security boundary for logs, separate workspaces must be deployed.
A single centralized workspace cannot easily enforce strict isolation without complex table-level RBAC, which is prone to configuration error and may not satisfy strict compliance audits.
3
Select the correct routing and governance mechanism.
Configure diagnostic settings to route subscription logs to their respective workspaces, using DeployIfNotExists policies for automation.
This ensures compliance is maintained automatically and securely without relying on manual configuration or direct individual RBAC assignments.

Key Concept

Log Analytics Workspace as an Administrative Boundary
Question 748Question

A multinational enterprise runs application workloads in the East US and Germany West Central regions. The German operations collect diagnostic logs containing metadata subject to strict European Union data sovereignty regulations, which mandate that all telemetry must remain resident within Germany. To manage these environments, the enterprise requires automated configuration of diagnostic logging for new resources, and the German security auditing team must be granted exclusive access to the German log files.

Which design strategy should you recommend to meet these requirements?

Show answer & explanation

Answer: Deploy separate Log Analytics workspaces in East US and Germany West Central, configure resources to route diagnostic logs to their local regional workspace, and manage access for the German auditors using Microsoft Entra security groups mapped to workspace roles.

Answer

Deploy separate Log Analytics workspaces in East US and Germany West Central, configure resources to route diagnostic logs to their local regional workspace, and manage access for the German auditors using Microsoft Entra security groups mapped to workspace roles.
The correct strategy deploys separate regional workspaces to satisfy European Union data sovereignty laws by keeping German operational data inside Germany. Furthermore, managing workspace access through Microsoft Entra security groups rather than individual account assignments aligns with identity governance best practices.

Step-by-Step Solution

1
Analyze data residency requirements.
Identified that EU data sovereignty regulations require German resource logs to remain within the Germany West Central region.
Data residency dictates physical workspace separation, precluding a single centralized workspace in East US.
2
Determine the proper governance approach for log configuration.
Determined that Azure Policy with 'DeployIfNotExists' is appropriate to automate diagnostic configurations, rather than blocking deployments using the 'Deny' effect.
Automating configuration ensures compliance without halting resource provisioning.
3
Design the access control model for security auditors.
Assigned workspace roles to a Microsoft Entra ID security group rather than directly to individual user accounts.
Group-based assignment reduces administrative overhead and aligns with Microsoft identity governance best practices.

Key Concept

Designing compliant Azure Monitor architectures that balance data residency regulations, policy-driven automation, and secure identity delegation.
Estimated Time:1m 30s
Question 749Question

A financial services company is establishing its presence in two Azure regions: Germany West Central and North Europe. The compliance department mandates that all logs containing customer financial data from the German region must remain within Germany to satisfy national data residency regulations. Workloads in North Europe have no data residency restrictions, and the company wants to optimize operational efficiency and reduce storage costs. Additionally, the security operations center requires that all newly created Azure Virtual Machines in both regions automatically configure their diagnostic logs to route to the designated Log Analytics workspaces without manual intervention. You need to design a monitoring, log routing, and access governance architecture that meets these requirements while adhering to Azure best practices.

Which architecture should you recommend?

Show answer & explanation

Answer: Deploy one Log Analytics workspace in Germany West Central and one Log Analytics workspace in North Europe. Create an Azure Policy using the DeployIfNotExists effect to automatically configure diagnostic settings for new virtual machines, and manage workspace access by assigning roles to Microsoft Entra security groups.

Answer

Deploy one Log Analytics workspace in Germany West Central and one Log Analytics workspace in North Europe. Create an Azure Policy using the DeployIfNotExists effect to automatically configure diagnostic settings for new virtual machines, and manage workspace access by assigning roles to Microsoft Entra security groups.
Deploying regional workspaces respects the local data residency requirement for German workloads. Using DeployIfNotExists automatically configures diagnostics for new VMs. Applying RBAC roles to Microsoft Entra security groups conforms to identity best practices.

Step-by-Step Solution

1
Analyze data residency constraints for the Germany West Central region.
Identify that a local Log Analytics workspace in Germany West Central is required to comply with national data sovereignty laws.
Log data containing customer financial data from Germany cannot be sent to North Europe due to regulatory restrictions, which rules out a single centralized workspace.
2
Determine the correct Azure Policy effect to automate diagnostic configuration on new Virtual Machines.
Select the DeployIfNotExists policy effect.
DeployIfNotExists automatically remediates non-compliant resources at deployment time by applying the diagnostic settings, whereas a Deny policy would block the deployment of VMs entirely.
3
Formulate the access governance model for the Log Analytics workspaces.
Establish Microsoft Entra security groups and assign Azure RBAC roles to them rather than individual accounts.
Assigning permissions directly to user accounts violates Azure Identity best practices for scalability and administrative management.

Key Concept

Designing regional vs centralized workspaces for regulatory compliance, automating resource configuration using DeployIfNotExists, and securing workspace access using Microsoft Entra group RBAC roles.
Question 750Question

A financial services company is designing the migration of an on-premises database cluster to Azure. The cluster hosts several databases that perform cross-database transactions using Distributed Transaction Coordinator (DTC) and run scheduled data extraction jobs using SQL Server Agent. The database security policy dictates that the data store must not be accessible via the public internet and must reside within a private network. The design must minimize administrative overhead.

Which two components should you include in the recommended design? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Azure SQL Managed Instance; A delegated subnet in an Azure Virtual Network

Answer

Azure SQL Managed Instance and a delegated subnet in an Azure Virtual Network
To satisfy the compatibility requirements for SQL Server Agent and Distributed Transaction Coordinator (DTC) while minimizing administrative overhead, the design must utilize Azure SQL Managed Instance (PaaS). To satisfy the network security requirement of preventing public internet access, Azure SQL Managed Instance must be deployed directly into a delegated subnet in an Azure Virtual Network, which provides private IP connectivity and network isolation.

Step-by-Step Solution

1
Analyze the application requirements: cross-database transactions using Distributed Transaction Coordinator (DTC) and SQL Server Agent jobs.
Identify that Azure SQL Managed Instance or SQL Server on Azure VMs support these features, whereas Azure SQL Database single database and elastic pools do not.
Compatibility requirements dictate the database engine features that must be supported.
2
Analyze the administrative constraint: minimize administrative overhead.
Filter out SQL Server on Azure Virtual Machines (IaaS) in favor of Azure SQL Managed Instance (PaaS).
PaaS solutions reduce management efforts for patching, backups, and high availability.
3
Analyze the network isolation requirement: the database must not be accessible via the public internet and must reside in a private network.
Determine that Azure SQL Managed Instance must be deployed into a delegated subnet within an Azure Virtual Network.
VNet injection provides native private IP addresses and isolates the Managed Instance from the public internet.

Key Concept

Selecting and configuring the appropriate Azure SQL relational database deployment option based on compatibility, management overhead, and network security requirements.
Question 751Question

An organization is designing a log routing and monitoring solution for application workloads deployed across two Azure regions: West US and North Europe. The design must meet the following requirements:
- Logs containing personally identifiable information (PII) from resources in North Europe must remain within the European Union (EU) to comply with data sovereignty regulations.
- Any newly deployed resource must be automatically configured to route its diagnostic logs without manual intervention.
- The monitoring logs must be retained for seven years, minimizing costs for long-term storage.
- Administrative access must follow the principle of least privilege, ensuring European operators can only access European logs, while central administrators can query logs across both regions.

Which two configurations should you include in the monitoring design?

Select all that apply

Show answer & explanation

Answer: Deploy separate Log Analytics workspaces in West US and North Europe, and route diagnostic logs to regional Azure Storage accounts with lifecycle policies.; Configure an Azure Policy definition with the DeployIfNotExists effect to remediate resources by deploying diagnostic settings automatically.

Answer

Deploy separate Log Analytics workspaces in West US and North Europe with Azure Storage accounts for long-term retention, and configure an Azure Policy definition with the DeployIfNotExists effect to automate diagnostic settings.
The solution requires separate regional Log Analytics workspaces to satisfy regional data residency and administrative isolation constraints. Using Azure Storage accounts with lifecycle management provides the most cost-efficient way to retain logs for seven years. Automated provisioning of diagnostic settings is accomplished via Azure Policy with a DeployIfNotExists effect.

Step-by-Step Solution

1
Address data sovereignty and residency constraints.
Identify that logs from North Europe cannot be sent to a West US workspace. Separate regional workspaces are required.
Data residency rules restrict PII log migration across international borders.
2
Select cost-effective long-term log retention.
Route diagnostic logs to Azure Storage accounts and implement lifecycle policies to archive data up to seven years.
Retaining active logs in a Log Analytics workspace for seven years is extremely expensive compared to archival storage tiers.
3
Identify the mechanism for automated configuration.
Apply Azure Policy using the DeployIfNotExists effect to deploy diagnostic settings automatically upon resource creation.
This automatically remediates compliance gaps without blocking deployment or requiring manual intervention.

Key Concept

Designing compliant, automated, and cost-effective log routing architectures across multiple regions using Azure Policy and Log Analytics.
Question 752Question

A retail company's cloud architecture includes a parent Management Group named Enterprise-MG that contains three subscriptions: Prod-Sub-01, Prod-Sub-02, and Dev-Sub-01. The governance team establishes the following design requirements:

- All virtual machines deployed in any subscription must use managed disks. Any attempt to deploy a virtual machine with unmanaged disks must be blocked.
- The development resource group Sandbox-RG, located in Dev-Sub-01, must be allowed to deploy virtual machines with unmanaged disks.
- All storage accounts deployed in any subscription must have diagnostic settings configured to send logs to a central Log Analytics workspace. If a storage account is deployed without diagnostic settings, the settings must be created automatically.

You need to design an Azure Policy solution that meets these requirements with the minimum administrative overhead.

Which two policy configurations should you include in the design?

Select all that apply

Show answer & explanation

Answer: Assign a policy definition that uses the Deny effect to enforce managed disks at the Enterprise-MG level, and add the Sandbox-RG scope to the assignment's exclusion list (notScopes).; Assign a policy definition that uses the DeployIfNotExists effect to configure storage account diagnostics at the Enterprise-MG level, and configure a managed identity for remediation.

Answer

Assigning a policy definition using the Deny effect to enforce managed disks at the Enterprise-MG level with Sandbox-RG excluded via notScopes, and assigning a policy definition using the DeployIfNotExists effect to configure storage diagnostics at the Enterprise-MG level with a managed identity.
Enforcing managed disks requires the Deny effect assigned at the parent management group level (Enterprise-MG) to ensure inheritance, with the Sandbox-RG resource group excluded via the notScopes parameter to allow unmanaged disks for development. Automatically configuring diagnostic settings for storage accounts requires the DeployIfNotExists (DINE) effect with a managed identity to perform remediation for resources that do not comply.

Step-by-Step Solution

1
Identify the mechanism to prevent the deployment of virtual machines with unmanaged disks across all subscriptions while allowing exceptions.
Determine that a policy definition using the Deny effect should be assigned at the parent management group level (Enterprise-MG) to ensure inheritance, with the Sandbox-RG resource group added to the assignment's 'notScopes' exclusion list to bypass the restriction.
This meets the security constraint at scale with the lowest administrative overhead by avoiding separate assignments per subscription.
2
Identify the mechanism to automatically configure storage account diagnostics when they are missing.
Determine that a policy definition using the DeployIfNotExists (DINE) effect should be assigned at the Enterprise-MG level, and a managed identity must be granted the necessary permissions to run the remediation task that deploys the diagnostic settings.
DeployIfNotExists checks for the existence of a child resource (diagnostic settings) and deploys it if it is missing, meeting the automation requirement.

Key Concept

Azure Policy effects and assignment scope exemptions
Question 753Question

An enterprise uses a multi-tier Azure landing zone structure under a single Root Management Group (RMG). One of the child management groups is named Legacy-Workloads. The security compliance team requires that all Azure Storage accounts enforce double encryption (infrastructure encryption).

You must design a policy governance strategy to meet the following requirements:
* All new and updated storage accounts must have infrastructure encryption enabled. If not, the deployment must be prevented.
* Existing storage accounts that do not have infrastructure encryption enabled must be flagged as non-compliant for reporting, but their current configurations must remain unaltered, and no automatic remediation tasks should be executed.
* For subscriptions tagged with environment: sandbox, the infrastructure encryption requirement must be recommended but not enforced, ensuring that deployments can succeed even if non-compliant, while their compliance status continues to be monitored and reported.
* The policy must not apply to any resources within the Legacy-Workloads management group.
* The strategy must minimize administrative overhead by using the fewest policy definitions.

Which policy design strategy should you recommend?

Show answer & explanation

Answer: Create a single policy definition with a parameterized effect. Assign the policy at the RMG level with the effect parameter set to Deny, adding the Legacy-Workloads management group and sandbox subscriptions to the assignment's exclusion scope (notScopes). Create a second assignment of the same policy at each sandbox subscription scope with the effect parameter set to Audit.

Answer

The correct strategy is to create a single policy definition with a parameterized effect, assign it at the Root Management Group level with the Deny effect (excluding both the Legacy-Workloads management group and the sandbox subscriptions), and assign the same policy definition at the sandbox subscriptions with the Audit effect.
The strategy of using a single policy definition with a parameterized effect, assigned at the Root Management Group level with Deny and excluding sandbox subscriptions, combined with a separate assignment set to Audit at the sandbox scope, is correct. Excluding the sandbox subscriptions from the Deny assignment ensures they are not blocked, while the child-level Audit assignment evaluates and reports compliance without blocking deployments. Excluding the Legacy-Workloads management group prevents any policy evaluation on its resources. Using a single definition minimizes administrative overhead.

Step-by-Step Solution

1
Determine the correct policy effect for blocking and monitoring without remediation.
The Deny effect blocks non-compliant resource deployments and flags existing non-compliant resources without altering them.
This satisfies the requirements to prevent new non-compliant resources while reporting existing ones without automatic remediation.
2
Determine how to handle the sandbox scopes.
The sandbox scopes require monitoring (Audit) but must not be blocked (Deny).
Since Azure Policy Deny assignments at a parent scope cannot be overridden by Audit assignments at a child scope, the sandbox scopes must be excluded from the parent Deny assignment using 'notScopes', and then targeted with a separate Audit assignment.
3
Determine how to handle the Legacy-Workloads management group.
The Legacy-Workloads management group must be excluded from the policy scope entirely.
Adding Legacy-Workloads to the 'notScopes' list of the RMG assignment ensures it is excluded.
4
Consolidate the policy definitions to minimize administrative overhead.
A single policy definition with a parameterized effect parameter can be assigned twice with different parameters (Deny and Audit).
This minimizes the number of custom policy definitions required, reducing administrative overhead.

Key Concept

Azure Policy effects evaluation, scope exclusions (notScopes), and parameterized assignments in a hierarchical landing zone.
Question 754Question

An enterprise company has an Azure environment with a management group structure consisting of a root management group named Contoso-MG and a child management group named Workloads-MG. You are designing an Azure Policy strategy to satisfy the following compliance requirements:

1. All Azure Key Vaults deployed in any subscription under Contoso-MG must have diagnostic settings automatically enabled to route all audit logs to a central Log Analytics workspace.
2. All Azure Storage accounts deployed in any subscription under Workloads-MG must have public network access blocked. Any attempt by administrators to deploy a storage account with public network access enabled must be prevented.
3. The public network access restriction for storage accounts must not apply to a specific resource group named dev-public-rg in the App-Sub-01 subscription under Workloads-MG.

You need to design the governance solution to meet these requirements with the least administrative effort.

Which two Azure Policy configurations should you include in your design? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: An Azure Policy definition assigned to the Contoso-MG management group scope using the DeployIfNotExists effect to configure Key Vault diagnostic settings.; An Azure Policy definition assigned to the Workloads-MG management group scope using the Deny effect to block public network access on storage accounts, with the dev-public-rg resource group scope added to the notScopes property.

Answer

The correct configurations are: (1) assigning a policy definition using the DeployIfNotExists effect at the Contoso-MG management group scope to configure Key Vault diagnostic settings, and (2) assigning a policy definition using the Deny effect at the Workloads-MG management group scope to block public network access on storage accounts, with the dev-public-rg resource group added to the notScopes property.
The correct design uses the DeployIfNotExists effect to automatically configure diagnostic settings for Key Vaults at the root management group scope, ensuring all subscriptions inherit the policy. To block public network access on storage accounts, the Deny effect is used on the workloads management group scope. To exempt the development resource group from the deny policy, its scope is added to the notScopes property of the policy assignment, which provides the least administrative overhead.

Step-by-Step Solution

1
Analyze the log routing requirement for Azure Key Vaults.
Since diagnostic settings must be automatically enabled without manual intervention, a policy with the DeployIfNotExists effect is required. Assigning this at the parent Contoso-MG scope ensures inheritance across all child subscriptions.
DeployIfNotExists automatically runs a template deployment when a resource is created or updated and found to be non-compliant, avoiding administrative overhead.
2
Analyze the requirement to prevent public network access on storage accounts.
Since attempts to create storage accounts with public access enabled must be blocked, the Deny effect must be used. Assigning this to Workloads-MG covers the target subscriptions.
The Deny effect prevents requests that do not comply with the policy definition, satisfying the requirement to block deployments.
3
Evaluate the exemption requirement for the development resource group.
The dev-public-rg resource group must be excluded from the public network access block. This is achieved by adding the resource group's resource ID to the notScopes property of the policy assignment at the Workloads-MG scope.
Using notScopes excludes specific sub-scopes from the policy evaluation, minimizing administrative overhead compared to managing separate policies or broad exemptions.

Key Concept

Azure Policy effects (DeployIfNotExists, Deny) and assignment exclusions (notScopes) are used to enforce security governance and compliance across management groups and subscriptions while accommodating specific workload exemptions.
Estimated Time:3m 0s
Question 755Question

Your company is designing a governance strategy for Azure resources. You need to implement Azure Policies that satisfy the following requirements:
- Prevent the deployment of virtual machines that do not use approved VM sizes.
- Automatically add a default department tag to resource groups when they are created without one.

Which two Azure Policy effects should you select to meet these requirements?

Select all that apply

Show answer & explanation

Answer: Deny; Modify

Answer

The correct effects to use are Deny to block non-compliant virtual machine deployments and Modify to automatically add missing tags to resource groups.
The correct strategy combines the Deny effect to block the creation of non-compliant resources (unapproved VM sizes) and the Modify effect to dynamically add missing tags during deployment.

Step-by-Step Solution

1
Analyze the first requirement: Prevent the deployment of virtual machines that do not use approved VM sizes.
To prevent or block a deployment that violates a compliance rule, the policy must use the Deny effect.
The Deny effect prevents a resource request from being sent to the resource provider, ensuring compliance is enforced proactively.
2
Analyze the second requirement: Automatically add a default department tag to resource groups when they are created without one.
To automatically add or update a property (like a tag) during resource creation, the policy must use the Modify effect.
The Modify effect allows the platform to inject properties or tags into the resource payload during deployment without blocking the deployment or requiring a separate deployment template.

Key Concept

Selecting appropriate Azure Policy effects to enforce compliance by blocking or automatically modifying resources during deployment.
Question 756Question

Your company is designing a monitoring solution for resources deployed in Azure. You need to ensure that all newly created Azure Key Vaults automatically have diagnostic settings enabled to route logs to a centralized Log Analytics workspace. If a Key Vault is deployed without diagnostic settings, the settings must be created automatically without preventing the deployment of the Key Vault itself. Which Azure Policy effect should you select to meet these requirements?

Show answer & explanation

Answer: Create an Azure Policy with the DeployIfNotExists effect to configure diagnostic settings automatically.

Answer

Create an Azure Policy with the DeployIfNotExists effect to configure diagnostic settings automatically.
The correct answer is to use the DeployIfNotExists policy effect. In Azure Policy, when you need to ensure that a resource (such as a Key Vault) has a diagnostic setting configured, but you do not want to block the deployment of the resource itself, DeployIfNotExists is the standard effect. It checks if the diagnostic setting sub-resource exists. If it does not, the policy runs a template deployment to create the diagnostic setting and route logs to the central Log Analytics workspace.

Step-by-Step Solution

1
Identify the primary requirement for configuring diagnostic settings.
Diagnostic settings must be automatically created when a Key Vault is deployed without them.
This establishes that a reactive or automatic remediation mechanism is required.
2
Evaluate the deployment constraints.
The policy must not prevent or block the deployment of the Key Vault.
This rules out the Deny effect, which blocks non-compliant resource creation.
3
Choose the correct Azure Policy effect and architecture.
The DeployIfNotExists effect is the standard policy effect for automatically deploying child resources like diagnostic settings without blocking the parent resource.
DeployIfNotExists allows the resource to be deployed first, then evaluates and applies the template to deploy the diagnostic settings.

Key Concept

Automating log routing and diagnostic setting enforcement using Azure Policy effects.
Question 757Question

An enterprise is designing a monitoring and log routing architecture for a healthcare application deployed across two Azure regions: UK South and Switzerland North. The application generates regional database diagnostic logs containing patient health information, and virtual machine performance metrics. The architecture must meet the following requirements:
- All database diagnostic logs must remain strictly within their region of origin due to regional data residency compliance regulations.
- Virtual machine performance metrics must be aggregated centrally in a single workspace in North Europe to facilitate global performance dashboards.
- Diagnostic settings must be automatically applied to any new database or virtual machine resource deployed in these regions.

Which two configurations should you include in the monitoring design? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Configure diagnostic settings on regional database resources to route logs to separate Log Analytics workspaces in UK South and Switzerland North respectively, and configure virtual machine diagnostic settings to route metrics to a centralized Log Analytics workspace in North Europe.; Create Azure Policy definitions using the DeployIfNotExists effect to automatically deploy the required diagnostic settings when new resources are provisioned.

Answer

Route database diagnostic logs to separate regional Log Analytics workspaces in UK South and Switzerland North, and route virtual machine performance metrics to a centralized Log Analytics workspace in North Europe; and create Azure Policy definitions using the DeployIfNotExists effect to configure diagnostic settings automatically.
To satisfy compliance requirements, sensitive database diagnostic logs must remain within their regions of origin (UK South and Switzerland North), necessitating separate regional workspaces. However, non-sensitive performance metrics can be consolidated centrally in North Europe to minimize overhead. Automated compliance is best achieved via Azure Policy using the DeployIfNotExists effect, which evaluates and deploys the necessary diagnostic settings directly upon resource creation, preventing manual misconfigurations without interrupting deployment flows.

Step-by-Step Solution

1
Analyze compliance and data residency requirements for database diagnostic logs.
Database diagnostic logs must remain strictly within the regions of origin (UK South and Switzerland North) due to regional regulations.
Ensures that sensitive patient health data does not cross international borders or sovereign regions.
2
Analyze aggregation requirements for performance metrics.
Virtual machine performance metrics can be aggregated in a centralized workspace located in North Europe.
Allows global operations teams to access consolidated metrics and dashboards from a single pane of glass while minimizing workspace sprawl.
3
Select the policy enforcement method for automatic configuration of diagnostic settings.
Deploy Azure Policy definitions with the DeployIfNotExists effect rather than the Deny effect.
DeployIfNotExists automatically applies the required diagnostic settings upon resource creation to ensure compliance, whereas a Deny policy would block the deployment of non-compliant resources without fixing them.

Key Concept

Designing a compliant, hybrid-residency monitoring architecture that segregates sensitive diagnostic data regionally while consolidating non-sensitive operational telemetry globally, enforced automatically via Azure Policy DeployIfNotExists remediation.
Question 758Question

An enterprise is designing a centralized monitoring and log routing architecture for its Azure environment. The architecture must accommodate several workloads with distinct security, compliance, and retention constraints. Match each operational log routing requirement on the left with its most appropriate Azure routing and destination configuration on the right.

Click a left item, then click its matching right item

Items

Administrative actions and management operations executed at the Azure subscription level.
Near-real-time application security events that must be streamed to an external, on-premises Security Information and Event Management (SIEM) system.
Database query audit logs that must be archived for seven years to meet regulatory compliance at the absolute minimum cost.
Resource-level diagnostic logs from multiple regions that must be analyzed centrally while enforcing access boundaries so team members only view logs for resources they own.

Matches

Show answer & explanation

Answer

Administrative actions at the subscription level match to a subscription-level diagnostic setting. Near-real-time SIEM logs match to the Event Hubs namespace. Database audit archives match to the Storage account with archive tier lifecycle policies. Regional diagnostic logs with restricted access match to the centralized Log Analytics workspace with resource-context Access Control Mode.
The correct matches align with Microsoft Azure best practices for log routing: Subscription-level actions go to Log Analytics via subscription-level diagnostic settings for central monitoring. External SIEM streams ingest logs from Azure Event Hubs to avoid polling latency. High-volume, cold-tier retention is routed to Azure Storage with lifecycle policies to minimize costs. Multi-region diagnostic logs are centralized in a single workspace where resource-context RBAC restricts visibility without the need for multiple workspaces.

Step-by-Step Solution

1
Identify the scope and frequency requirements for each log source.
The workloads span subscription-level auditing, real-time external streaming, long-term cold archiving, and decentralized access with centralized storage.
This establishes the constraints and targets for log routing.
2
Select the most cost-effective and compliant destination for long-term retention.
Azure Storage account with archive tier lifecycle rules is chosen for the 7-year audit logs.
Log Analytics ingestion and retention costs are too high for long-term cold storage.
3
Determine the streaming mechanism for the external SIEM integration.
Azure Event Hubs is mapped to the SIEM requirement.
Event Hubs provides low-latency, real-time ingestion capabilities suited for SIEM ingestion.
4
Determine the optimal workspace configuration for resource access boundaries.
A centralized Log Analytics workspace with resource-context access control is selected.
This configuration allows users to query logs of resources they own without needing access to the workspace, avoiding workspace duplication.

Key Concept

Designing a centralized log routing architecture in Azure that satisfies ingestion latency, retention costs, and security boundary constraints using Azure Monitor, Log Analytics, Event Hubs, and Storage Accounts.
Question 759Question

An organization has multiple application workloads deployed across separate resource groups in a single Azure region. Each workload is managed by a different support team. You are designing a monitoring and log routing architecture that must satisfy the following requirements:

* All resource diagnostic logs must be collected and stored for centralized compliance analysis.
* If a new or existing resource is deployed without diagnostic settings, they must be automatically configured to route logs to the destination.
* Support teams must only be allowed to view the diagnostic logs of the resources within their respective resource groups.
* The administrative overhead for managing log access and workspace configurations must be minimized.

Which design solution should you recommend?

Show answer & explanation

Answer: Deploy a single centralized Log Analytics workspace. Apply an Azure Policy with the DeployIfNotExists effect to configure diagnostic settings. Assign the Monitoring Reader role to Microsoft Entra security groups at the resource group level to enable resource-context log access.

Answer

Deploy a single centralized Log Analytics workspace. Apply an Azure Policy with the DeployIfNotExists effect to configure diagnostic settings. Assign the Monitoring Reader role to Microsoft Entra security groups at the resource group level to enable resource-context log access.
A single centralized Log Analytics workspace minimizes workspace management overhead. Using Azure Policy with the DeployIfNotExists effect automatically creates diagnostic settings to route resource logs to the workspace. By assigning the Monitoring Reader role to Microsoft Entra security groups at the resource group level, support teams can view logs for their resources from the centralized workspace using resource-context access, without needing permissions on the workspace itself.

Step-by-Step Solution

1
Select a single Log Analytics workspace for the region.
Minimizes administrative overhead and avoids managing multiple workspaces.
Designing multiple regional workspaces for isolation is unnecessary when resource-context RBAC can restrict log access.
2
Configure Azure Policy with the DeployIfNotExists effect for resource diagnostics.
Automatically deploys diagnostic settings pointing to the centralized workspace for new and existing resources.
DeployIfNotExists remediates resources automatically, whereas a Deny effect would block deployments and disrupt CI/CD pipelines.
3
Assign the Monitoring Reader role to Microsoft Entra security groups at the resource group scope.
Enables resource-context logging, letting users view logs for only the resources they have access to, without workspace-level permissions.
Assigning RBAC to groups rather than individual users ensures scalable governance and security.

Key Concept

Centralized log routing with resource-context access control and automated compliance remediation via DeployIfNotExists policy.
Question 760Question

An organization manages its cloud resources using an Azure Management Group hierarchy. A management group named CoreServices-MG contains subscriptions used for shared network infrastructure. The security team mandates that all virtual networks deployed within CoreServices-MG must have diagnostic settings configured to send traffic metrics to a central Log Analytics workspace. The deployment of virtual networks must proceed without interruption even if the diagnostic settings are not defined during creation, but the diagnostic settings must be automatically configured immediately after deployment. Which Azure Policy effect should you specify in the policy definition to meet these requirements?

Show answer & explanation

Answer: DeployIfNotExists

Answer

DeployIfNotExists
The DeployIfNotExists effect is the correct choice because it evaluates a resource during creation or update, and if the resource does not have the specified sub-resource (in this case, diagnostic settings), it automatically deploys the template to create it. This ensures compliance without blocking the deployment of the parent resource.

Step-by-Step Solution

1
Analyze the business requirements for resource deployment and remediation.
The solution requires that virtual network deployment must not be blocked (meaning Deny cannot be used), but the diagnostic settings must be configured automatically (meaning Audit cannot be used alone).
Understanding the constraints is necessary to narrow down the correct policy effect.
2
Compare the capabilities of Modify and DeployIfNotExists for configuring child/extension resources.
Modify is restricted to changing properties and tags on the target resource itself. Diagnostic settings are extension resources, which require DeployIfNotExists to deploy the template.
Distinguishing between resource property modification and secondary resource deployment ensures correct governance design.
3
Select the policy effect that deploys resources asynchronously.
DeployIfNotExists is chosen because it triggers a template deployment if the specified condition (missing diagnostic settings) is met, following successful creation of the parent resource.
DeployIfNotExists meets all criteria of automatic remediation without blocking the initial deployment.

Key Concept

Azure Policy effects determine the action taken when compliance rules are evaluated. DeployIfNotExists is used for automated remediation of missing child or extension resources without blocking parent deployments.
Estimated Time:1m 30s
PreviousPage 38 / 60Next
All practice questions — Microsoft Azure Solutions Architect (AZ-305) | Examkin