AZ-104 Implement and Manage Virtual Networking Practice Question
Why is centralized logging valuable during security incident response?
⚠ Common exam trap
A common mix-up: candidates think centralized logging is a security control that prevents attacks (like a firewall or IDS), rather than recognizing it as a detective control that aids in post-incident analysis and correlation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It makes related events from many devices easier to collect and correlate.
Centralized logging aggregates logs from multiple sources (e.g., Azure VMs, network security groups, Azure Firewall) into a single repository like Azure Log Analytics or Azure Sentinel. This correlation enables security analysts to identify patterns across devices, such as a chain of events from an initial breach to lateral movement, which is critical for incident response. Without centralization, manually correlating timestamps and log formats from disparate systems would be impractical during an active attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It makes related events from many devices easier to collect and correlate.
Why this is correct
Centralized logging aggregates events from firewalls, endpoints, servers, and cloud services into a single time-indexed repository, allowing analysts to reconstruct a full attack chain by correlating related activities across devices. Instead of examining isolated logs, investigators can query for indicators of compromise that span an entire network, significantly reducing the time to detect and respond to incidents.
- ✗
It guarantees that attacks cannot succeed.
Why it's wrong here
Centralized logging cannot guarantee that attacks will never succeed because it is passive—it only captures events that have already occurred. Even with real-time alerting, an intrusion can partially or fully execute before a security team or automated system can intervene; prevention requires active controls like endpoint detection and response, firewalls, and intrusion prevention systems. Logging supports post-incident analysis and helps improve defenses, but it is not a barrier to attack execution.
When this WOULD be correct
If the exam question asked about the effectiveness of security measures in preventing attacks, and specifically mentioned that a certain security architecture guarantees attack prevention, then this option could be correct. For example, a question could state that a security system is designed to block all unauthorized access, thus guaranteeing that attacks cannot succeed.
- ✗
It replaces access control mechanisms.
Why it's wrong here
Centralized logging is inherently a detective control—it records user and system activity after the fact, but it cannot enforce security policies, verify identities, or authorize resource access. Access control depends on mechanisms such as role-based access control, attribute-based policies, and multi-factor authentication, which operate at the authentication and authorization layer. Logging provides evidence of who accessed what, but it in no way substitutes for these preventive security controls.
When this WOULD be correct
In a question that asks about the benefits of integrating security measures, such as logging and access control, one might argue that centralized logging can enhance the effectiveness of access control by providing insights into access patterns and potential breaches. This could make it a correct answer in that context.
- ✗
It forces all systems to use one VLAN.
Why it's wrong here
Centralized logging is a logical data-collection architecture, not a physical or logical network configuration; it determines where log records are sent from, not how segments are structured. VLANs are Layer 2 segmentation mechanisms designed to isolate broadcast traffic and enforce network boundaries, which are orthogonal to log shipping. In fact, forcing all systems onto one VLAN would eliminate segmented security zones and increase lateral movement risk, making it a counterproductive and unrelated idea.
When this WOULD be correct
If the exam question were to ask about network segmentation strategies that enhance security by isolating traffic, then stating that forcing all systems to use one VLAN could be seen as a correct answer in the context of simplifying network management and monitoring.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓It makes related events from many devices easier to collect and correlate.Correct answer▾
Why this is correct
Centralized logging aggregates events from firewalls, endpoints, servers, and cloud services into a single time-indexed repository, allowing analysts to reconstruct a full attack chain by correlating related activities across devices. Instead of examining isolated logs, investigators can query for indicators of compromise that span an entire network, significantly reducing the time to detect and respond to incidents.
✗It guarantees that attacks cannot succeed.Wrong answer — click to see why▾
Why this is wrong here
This option is wrong because centralized logging does not prevent attacks; it merely helps in detecting and analyzing them after they occur. Security measures must be implemented to actually prevent attacks from succeeding.
★ When this WOULD be the correct answer
If the exam question asked about the effectiveness of security measures in preventing attacks, and specifically mentioned that a certain security architecture guarantees attack prevention, then this option could be correct. For example, a question could state that a security system is designed to block all unauthorized access, thus guaranteeing that attacks cannot succeed.
Why candidates choose this
Candidates may find this option tempting because it suggests a strong security posture, appealing to the desire for absolute protection in cybersecurity. The idea of guaranteed prevention aligns with common misconceptions about security solutions.
✗It replaces access control mechanisms.Wrong answer — click to see why▾
Why this is wrong here
This option is wrong because centralized logging does not replace access control mechanisms; rather, it complements them by providing visibility into access attempts and security events. Access control mechanisms are essential for determining who can access what resources, independent of logging.
★ When this WOULD be the correct answer
In a question that asks about the benefits of integrating security measures, such as logging and access control, one might argue that centralized logging can enhance the effectiveness of access control by providing insights into access patterns and potential breaches. This could make it a correct answer in that context.
Why candidates choose this
Candidates may find this option tempting because they might confuse the role of logging with that of access control, believing that effective logging could inherently secure systems by replacing the need for access controls.
✗It forces all systems to use one VLAN.Wrong answer — click to see why▾
Why this is wrong here
Option D is incorrect because centralized logging does not dictate network architecture or enforce VLAN configurations; it focuses on aggregating log data for analysis. Centralized logging can operate across different VLANs without forcing all systems into a single VLAN.
★ When this WOULD be the correct answer
If the exam question were to ask about network segmentation strategies that enhance security by isolating traffic, then stating that forcing all systems to use one VLAN could be seen as a correct answer in the context of simplifying network management and monitoring.
Why candidates choose this
Candidates may find this option tempting because they might associate centralized logging with network management practices, mistakenly believing that it implies a unified network architecture or VLAN configuration for better data collection.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Dynamic Membership Groups
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.