Soru

Zorluk: OrtaMonitoring and Log Routing Solutions

An enterprise is designing a comprehensive monitoring and log routing architecture for various workloads across Azure subscriptions. You need to match the administrative and operational requirements with the most appropriate Azure Monitor destination or feature to minimize costs and administrative overhead.

Match the requirements on the left to their corresponding destinations or features on the right.

  • Retain application diagnostic logs for seven years to meet regulatory compliance while minimizing storage costs.Azure Storage account with lifecycle management policies
  • Collect, correlate, and run complex Kusto Query Language (KQL) queries on resource telemetry across multiple subscriptions.Azure Monitor Log Analytics workspace
  • Stream Azure resource logs in near-real-time to an external third-party Security Information and Event Management (SIEM) system.Azure Event Hubs
  • Monitor IP traffic patterns, identify traffic hotspots, and analyze security group rule hits for virtual networks.Azure Network Watcher Traffic Analytics

Cevap

The correct matches are: (1) Retaining logs for seven years to minimize costs matches Azure Storage account; (2) Running KQL queries and correlating telemetry matches Azure Monitor Log Analytics workspace; (3) Streaming logs to an external SIEM matches Azure Event Hubs; (4) Monitoring IP traffic patterns and NSG rules matches Azure Network Watcher Traffic Analytics.
Each requirement maps to a specific destination in Azure Monitor: Azure Storage accounts provide low-cost long-term archiving; Log Analytics workspaces enable centralized KQL querying; Azure Event Hubs provides near-real-time integration with external SIEMs; and Traffic Analytics processes NSG flow logs to analyze network traffic patterns.

Adım Adım Çözüm

1
Analyze the log retention and cost requirement.
Identify that seven-year retention requires cold storage to minimize costs. Azure Storage accounts with lifecycle management are the most cost-effective choice for long-term archiving.
Log Analytics workspaces charge significant fees for data retention beyond the default period, whereas Azure Storage Archive tier is highly cost-effective.
2
Analyze the correlation and query requirement.
Identify that running Kusto Query Language (KQL) queries across subscriptions requires a centralized repository.
Azure Monitor Log Analytics workspace provides the KQL engine and native cross-workspace or cross-subscription querying capabilities.
3
Analyze the integration requirement for external SIEM.
Identify the mechanism for streaming logs in near-real-time to third-party endpoints.
Azure Event Hubs serves as the event ingestor and message bus used to route diagnostic logs to external systems like Splunk or QRadar.
4
Analyze the network security and flow logging requirement.
Identify the tool that visualizes and analyzes NSG flow logs.
Azure Network Watcher Traffic Analytics uses NSG flow logs to provide dashboard visualizations of traffic patterns and security rule behaviors.

Anahtar Kavram

Matching Azure log sources and regulatory requirements to the correct Azure Monitor diagnostic destinations.
Tahmini Süre:2m 0s
Bu soruyu puanla