Microsoft Certified: Azure Solutions Architect ExpertDesign data storage solutionsMedium

A financial institution needs to store audit logs from various applications. These logs are generated continuously, often in unstructured or semi-structured formats (JSON, plain text). The primary use case is for security analysis, compliance audits, and troubleshooting, which involves querying historical data over long periods (years) using complex text searches and aggregations. The solution must be highly scalable to accommodate petabytes of data and offer fast analytical query performance. Which Azure data storage solution should be chosen?

  1. AAzure SQL Database
  2. BAzure Data Lake Storage Gen2 with Azure Databricks
  3. CAzure Cosmos DB
  4. DAzure Data Explorer (Kusto)
Show answer & explanation

Correct answer: D. Azure Data Explorer (Kusto)

Azure Data Explorer (Kusto) is specifically designed for high-performance ingestion and querying of telemetry, logs, and time-series data. It excels at complex text searches, aggregations, and analytical queries over large volumes of semi-structured data, making it ideal for audit logs and security analysis.

Why the other options are wrong

  • A. Azure SQL Database is a relational database and not optimized for ingesting and querying petabytes of unstructured/semi-structured log data with complex text searches.
  • B. Azure Data Lake Storage Gen2 stores the data, but Azure Databricks is a processing engine. While capable, Azure Data Explorer offers a more integrated and optimized solution specifically for log and telemetry analytics with native KQL.
  • C. Azure Cosmos DB is a transactional NoSQL database, not optimized for petabyte-scale analytical queries over historical log data with complex aggregations.

Azure Data Explorer (Kusto)

A fast, fully managed data analytics service for real-time analysis of large volumes of data streaming from applications, websites, IoT devices, and more. It uses the Kusto Query Language (KQL) for powerful ad-hoc queries.

  • Optimized for log, telemetry, and time-series data
  • High-performance ingestion and querying
  • Uses Kusto Query Language (KQL)
  • Scales to petabytes of data

Memory trick: Explorer finds insights, Synapse warehouses it, Data Lake stores it all.

More Design data storage solutions questions