You plan to audit an Azure SQL database named sql1. The audit destination must allow querying events with the Kusto query language and require minimal administrative effort. Which audit destination should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: a Log Analytics workspace.
Why this is the answer
A Log Analytics workspace is the correct choice because it natively supports Kusto Query Language (KQL) for querying collected logs, including Azure SQL database audit events. This provides powerful analytical capabilities with minimal administrative overhead once configured. An event hub is designed for real-time data streaming and would require additional services (like Azure Stream Analytics or Azure Functions) to process and store data for querying, increasing complexity. A storage account can store audit logs, but querying them directly with KQL is not natively supported; you would typically need to export them to another service like Log Analytics or Azure Data Explorer for KQL analysis.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed