Courseiva

AZ-104 Monitor and Maintain Azure Resources Practice Question

You manage an Azure subscription that contains a virtual machine named VM1 running a line-of-business application. The application writes diagnostic data to the Windows Event Log. The security team requires that all events from the 'Application' log with a level of Error or Critical be retained for 30 days and be searchable by using Kusto Query Language (KQL). You need to configure the minimum components required to meet these requirements. What should you do?

⚠ Common exam trap

The trap here is assuming the legacy Log Analytics agent (MMA) can filter by event level during collection, but it cannot and is deprecated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install the Azure Monitor Agent (AMA) on VM1, create a Data Collection Rule (DCR) that collects the Application log filtered to Error and Critical levels, and associate the DCR with VM1. Send the data to a Log Analytics workspace with a 30-day retention.

To collect Windows Event Logs with filtering and send to Log Analytics for KQL querying, Azure Monitor Agent (AMA) and Data Collection Rules (DCRs) are the current standard. The DCR allows specifying the log name and filtering by level, and the Log Analytics workspace retention can be set to 30 days. This solution meets all requirements: collection, filtering, retention, and querying.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Install the Azure Monitor Agent (AMA) on VM1, create a Data Collection Rule (DCR) that collects the Application log filtered to Error and Critical levels, and associate the DCR with VM1. Send the data to a Log Analytics workspace with a 30-day retention.

    Why this is correct

    This is correct because Azure Monitor Agent uses Data Collection Rules to define what data to collect, including filtering Windows Event Logs by level. The DCR specifies the destination Log Analytics workspace, and the workspace retention can be set to 30 days. This approach meets the requirements for collection, filtering, retention, and KQL querying.

  • ✗

    Create an Event Grid subscription for VM1's system topic to capture Application log events, and route them to an Azure Function that writes to a Log Analytics workspace with 30-day retention.

    Why it's wrong here

    This fails because Event Grid does not natively capture Windows Event Log entries from a VM. Event Grid is for Azure resource events, not guest OS logs. Implementing a custom function would be overly complex and not the standard method. The correct approach uses Azure Monitor Agent and Data Collection Rules.

  • ✗

    Enable Azure Diagnostics extension on VM1, configure it to send Application log data to an Azure Storage account, and set a lifecycle management policy to delete blobs after 30 days.

    Why it's wrong here

    This fails because storing data in Azure Storage does not provide KQL querying. While lifecycle management can enforce retention, the security team requires searchable data using KQL, which is only available in Log Analytics. Azure Diagnostics extension can send to Storage but not directly to Log Analytics with filtering.

  • ✗

    Install the Log Analytics agent (MMA) on VM1 and configure it to collect the Application log. Send the data to a Log Analytics workspace with a 30-day retention.

    Why it's wrong here

    This fails because the legacy Log Analytics agent (MMA) is deprecated and does not support filtering by event level during collection. It would collect all events from the Application log, not just Error and Critical, potentially exceeding ingestion costs and not meeting the precise filtering requirement. Additionally, MMA is being retired in favor of AMA.

About these practice questions

This AZ-104 question is part of Courseiva's 1,053-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.