You have an Azure AD tenant named contoso.com. You must configure diagnostic settings to retain logs for two years, query logs using Kusto Query Language, and minimize administrative effort. Where should you store the logs?
Choose an answer
Tap an option to check your answer.
Correct answer: an Azure Log Analytics workspace.
Why this is the answer
An Azure Log Analytics workspace is the correct choice because it natively supports Kusto Query Language (KQL) for querying logs and offers flexible retention policies, including two years, directly within the service. This minimizes administrative effort compared to other options. An Azure Event Hub is designed for real-time streaming and doesn't inherently provide long-term storage or KQL querying. An Azure Storage account can store logs for extended periods but requires additional services (like Azure Data Explorer or a custom solution) to enable KQL querying, increasing administrative overhead.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed