Soru

Zorluk: OrtaMonitoring and Log Routing Solutions

A retail company operates a multi-tier e-commerce platform deployed in the East US 2 and UK South regions. The company's compliance policy dictates that all auditing and diagnostic data generated in UK South must remain within the UK geographic boundary. Regional administrators in each region must only be able to view logs for resources within their administrative scope. The security team must be able to run queries across logs from both regions. Which of the following log routing and workspace architectures should you recommend?

  1. Deploy one Log Analytics workspace in East US 2 and another in UK South. Route diagnostic logs from resources in each region to their respective regional workspace. Grant workspace access to regional administrators using Microsoft Entra groups assigned to the respective workspace.Cevap
  2. B
    Deploy a single centralized Log Analytics workspace in East US 2. Route all regional diagnostic logs to this workspace, and configure workspace-context Access Control (IAM) using individual user assignments to restrict access by region.
  3. C
    Deploy one Log Analytics workspace in East US 2 and another in UK South. Route diagnostic logs to their respective regional workspaces. Grant regional administrators Owner permissions at the subscription level, and use an Azure Policy with a Deny effect to prevent them from reading logs outside their region.
  4. D
    Deploy one Log Analytics workspace in East US 2 and another in UK South. Route diagnostic logs to their local workspaces. Grant workspace-level access by assigning the Reader role directly to the individual Azure user accounts of the regional administrators.

Cevap

Deploy two separate Log Analytics workspaces (one in East US 2 and one in UK South) to satisfy regional data residency requirements, and manage access to these workspaces using Microsoft Entra groups.
Deploying separate regional Log Analytics workspaces ensures that data residency constraints are met because the logs for UK South remain within the UK geographic boundary. The security team can still perform cross-workspace queries when needed. Access is restricted regionally by granting workspace-level permissions to regional administrators using Microsoft Entra groups, which satisfies both isolation and security best practices.

Adım Adım Çözüm

1
Analyze compliance and data residency constraints.
Determine that since UK South data must remain within the UK, a single centralized workspace in East US 2 cannot be used. We must deploy separate workspaces in both East US 2 and UK South.
Storing UK logs in East US 2 violates the data residency requirement.
2
Configure diagnostic log routing.
Configure Azure resources to send diagnostic logs to their local regional workspace.
This aligns the logging pipeline with data residency boundaries.
3
Implement access control for regional administrators.
Assign workspace access to regional administrators using Microsoft Entra security groups.
Using Entra groups is the recommended practice for scalable and manageable access control, avoiding direct user assignments.

Anahtar Kavram

Designing regional Log Analytics workspaces to satisfy compliance constraints and setting up secure workspace access control using Microsoft Entra groups.
Tahmini Süre:1m 30s
Bu soruyu puanla