Q: 3
Which audit log destination should you use to meet the monitoring requirements?
Options
Discussion
Makes sense to pick C for monitoring, Log Analytics is designed for analysis and alerting. Haven't seen anyone use B for this.
Business Critical, Gen5. Business Critical gives lower latency and Gen5 offers the best memory per vCore. Think that's what Microsoft wants here but open to debate if anyone's seen a different combo.
Yeah, C makes sense here. Log Analytics is designed for monitoring within Azure, offering dashboards and alerts out of the box. If the question wanted integration with something outside Azure, maybe B would fit better, but for native monitoring and analysis you want Log Analytics. Pretty confident on this, but let me know if you see it differently!
Why not B here? It streams logs out but doesn’t really have any tools for alerting or analysis on its own, so I’m thinking that’s not what the question means by "monitoring." Anyone using Event Hubs as the main monitoring destination for audit logs, or is everyone going with C?
C tbh, Log Analytics is always the monitoring go-to in Azure for this type of logging.
Its C. Log Analytics is built for monitoring and alerting directly in Azure, pretty sure that's what they want here.
B , a few practice exams put Event Hubs as the answer for SIEM style monitoring.
Definitely C for this one.
Had something like this in a mock-it's Business Critical tier and Gen5 for max memory-to-vCore and lowest latency.
C , Log Analytics is all about real analysis and alerting, while Storage is more for retention and Event Hubs is just for streaming out. Pretty sure C fits what they want for monitoring but let me know if I'm missing something.
Be respectful. No spam.