Courseiva
Question 1,067 of 1,049
Implement and Manage Virtual NetworkingmediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

Which statement best explains why centralized logging is valuable in security operations?

⚠ Common exam trap

Many candidates think centralized logging actively prevents security incidents (like a firewall or IDS), when in fact it is a passive detective control that improves visibility and post-incident analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It improves visibility by collecting events from multiple devices in one place for review and investigation.

Centralized logging aggregates security events (e.g., Windows Event Log, syslog, Azure Activity Log) from multiple sources into a single repository like Azure Log Analytics or a SIEM. This consolidation enables security analysts to correlate events across devices, detect patterns indicative of attacks, and perform efficient forensic investigations without needing to access each device individually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • It improves visibility by collecting events from multiple devices in one place for review and investigation.

    Why this is correct

    Centralized logging aggregates syslog messages, Windows Event Logs, Azure Activity Logs, and resource diagnostic logs into a single Log Analytics workspace. This consolidation enables security and operations teams to search, correlate, and investigate events across all devices and workloads without jumping between multiple consoles. Because logs are stored in one queriable repository, incident response and root-cause analysis become significantly faster and more effective.

  • It guarantees that no unauthorized action can occur.

    Why it's wrong here

    Logging is fundamentally a detective control, not a preventive one; it records what happened after the fact and cannot stop an unauthorized action from occurring. Even with real-time alerting, there is a window during which the action has already taken place before detection and response can begin. Preventing unauthorized actions requires separate technical enforcements such as conditional access policies, RBAC, and resource locks.

    When this WOULD be correct

    In a different exam scenario, a question might ask about the benefits of implementing a comprehensive security framework. In that context, if the question emphasized the role of logging in enforcing security policies, option B could be seen as correct, suggesting that centralized logging contributes to preventing unauthorized actions through policy enforcement.

  • It replaces the need for NTP and authentication.

    Why it's wrong here

    Centralized logging depends on accurate, synchronized timestamps from NTP to correlate events correctly, and it depends on authentication and RBAC to control who can access the log data. Rather than replacing these controls, a robust logging solution reinforces them by providing an audit trail of administrative activity. Removing NTP or authentication would quickly degrade the reliability and security of the log collection itself.

    When this WOULD be correct

    In a question asking about the integration of various network services, one could argue that centralized logging systems can operate without NTP and authentication, focusing solely on log collection. In this context, if the question specified that centralized logging could function independently of these services, option C could be considered correct.

  • It automatically assigns IP addresses to monitoring systems.

    Why it's wrong here

    Dynamic IP address assignment is performed by DHCP (or static configuration), not by a logging system. Centralized logging only receives and stores event data; it has no mechanism for IP address management or network configuration. Even if log sources are discovered via network scanning, the logging platform does not assign addresses to the agents or devices sending data.

    When this WOULD be correct

    In a different exam scenario where the question asks about the functionalities of a network monitoring system that includes DHCP services, option D could be correct if the context is about how monitoring systems can manage IP address allocation for devices on a network.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

It improves visibility by collecting events from multiple devices in one place for review and investigation.Correct answer

Why this is correct

Centralized logging aggregates syslog messages, Windows Event Logs, Azure Activity Logs, and resource diagnostic logs into a single Log Analytics workspace. This consolidation enables security and operations teams to search, correlate, and investigate events across all devices and workloads without jumping between multiple consoles. Because logs are stored in one queriable repository, incident response and root-cause analysis become significantly faster and more effective.

It guarantees that no unauthorized action can occur.Wrong answer — click to see why

Why this is wrong here

This option is wrong because centralized logging does not prevent unauthorized actions; it merely collects and stores logs for analysis. Security operations rely on other measures, such as access controls and monitoring, to prevent unauthorized activities.

★ When this WOULD be the correct answer

In a different exam scenario, a question might ask about the benefits of implementing a comprehensive security framework. In that context, if the question emphasized the role of logging in enforcing security policies, option B could be seen as correct, suggesting that centralized logging contributes to preventing unauthorized actions through policy enforcement.

Why candidates choose this

Candidates may find this option tempting because it implies a strong security posture, suggesting that centralized logging could inherently prevent unauthorized actions. This reflects a common misconception that logging alone can secure systems without additional security measures.

It replaces the need for NTP and authentication.Wrong answer — click to see why

Why this is wrong here

This option is wrong because centralized logging does not replace the need for Network Time Protocol (NTP) or authentication; these are separate functions that ensure accurate time synchronization and secure access to systems, respectively.

★ When this WOULD be the correct answer

In a question asking about the integration of various network services, one could argue that centralized logging systems can operate without NTP and authentication, focusing solely on log collection. In this context, if the question specified that centralized logging could function independently of these services, option C could be considered correct.

Why candidates choose this

Candidates might choose this option due to a misunderstanding of centralized logging's role, mistakenly believing it encompasses all aspects of system management, including time synchronization and authentication, leading to confusion about its capabilities.

It automatically assigns IP addresses to monitoring systems.Wrong answer — click to see why

Why this is wrong here

This option is wrong because centralized logging does not involve the automatic assignment of IP addresses; it focuses on aggregating logs for analysis rather than managing network configurations.

★ When this WOULD be the correct answer

In a different exam scenario where the question asks about the functionalities of a network monitoring system that includes DHCP services, option D could be correct if the context is about how monitoring systems can manage IP address allocation for devices on a network.

Why candidates choose this

Candidates might choose this option due to a misunderstanding of network management concepts, conflating centralized logging with network services like DHCP, leading to confusion about their distinct roles in IT operations.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.