Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Which THREE of the following are required to collect Windows security events into Microsoft Sentinel?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Defender for Cloud (a security management service) with a data collection agent, or think Azure Policy can be used to collect logs, when in fact only the combination of a Log Analytics workspace, a DCR, and the AMA fulfills the requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log Analytics workspace

A Log Analytics workspace is required because Microsoft Sentinel is built on top of it; all security events collected by Sentinel are stored in the workspace's tables, and Sentinel uses the workspace as its data repository for analytics, alerting, and investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Log Analytics workspace

    Why this is correct

    A Log Analytics workspace is the mandatory ingestion destination for all log data collected by the Azure Monitor Agent. Without a workspace, the agent has no target endpoint to send events to, and there is no table structure to store Windows Event logs or custom logs. The workspace also defines data retention, permissions, and can be used to query collected logs with log analytics queries. Even if a data collection rule is configured, it must point to an existing workspace to actually receive the data.

  • ✓

    Data collection rule (DCR)

    Why this is correct

    A data collection rule (DCR) is the configuration object that defines what telemetry to collect and where to send it. For Windows machines, the DCR specifies data sources such as event log channels, event IDs, performance counters, and custom logs, and then maps them to a destination Log Analytics workspace. The Azure Monitor Agent will only collect data after a DCR is associated with the machine, and each DCR can apply to multiple machines, enabling central collection policy. Without a DCR, even with the agent installed, no data is collected because the agent has no instructions.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy is not required to collect Windows events, though it is often used to simplify large-scale deployment. Policy can automatically install the Azure Monitor Agent and associate data collection rules via an initiative like 'Configure Windows machines to run Azure Monitor Agent and associate to DCR.' However, you can manually install the agent and attach a DCR through the portal, CLI, or ARM templates, and collection will work exactly the same. Policy merely automates compliance and provisioning; it does not participate in the data collection path itself.

  • ✓

    Azure Monitor Agent (AMA)

    Why this is correct

    The Azure Monitor Agent (AMA) is the actual collection service running on the Windows machine, responsible for reading event log entries and forwarding them to the workspace defined in the data collection rule. It is the current generation agent that replaces the older Log Analytics agent and is required for all DCR-based collection. The agent runs as a Windows service and uses the data collection endpoint to securely transmit data, respecting workspace authentication and network configuration. Without AMA, there is no process to read the Windows event logs, making collection impossible.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is not required for collecting Windows security events or general event logs. Defender for Cloud may enable its own security event collection by installing the Azure Monitor Agent and creating its own data collection rules, but this is an optional feature tied to the Defender plan. Users can collect Windows Event logs independently by creating a custom DCR and assigning it to their machines, without any Defender for Cloud license or binding. The only thing mandatory is a workspace, a DCR, and the AMA agent; any security tooling is supplementary.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.