You must centralize platform logs from several Azure Key Vaults. Requirements: 1) query logs with KQL, 2) retain raw logs for 7 years to meet regulatory needs, and 3) stream logs to a third-party SIEM via Event Hubs. You want to minimize the number of configuration objects. What should you configure on each Key Vault?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a single diagnostic setting that sends the required log categories to: a Log Analytics workspace, a Storage account for archive, and an Event Hubs namespace.
Why this is the answer
A single diagnostic setting on each Key Vault can send logs to multiple destinations simultaneously, fulfilling all requirements with minimal configuration objects. This allows querying with KQL in Log Analytics, 7-year retention in a Storage account, and streaming to Event Hubs for the SIEM. Creating three separate diagnostic settings is redundant and increases management overhead. Activity log export captures subscription-level control plane operations, not Key Vault platform logs. Azure Policy can enforce diagnostic settings but doesn't directly route logs; exporting from Log Analytics to Storage and Event Hubs is an unnecessary extra step and doesn't meet the "raw logs" requirement for 7 years in storage.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed