AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization uses Azure Monitor to monitor a fleet of 500 VMs running Windows Server. You need to collect security event logs (Event ID 4625 for failed logons) from all VMs and send them to a Log Analytics workspace. The solution must support centralized configuration and be scalable. You also want to filter out high-volume noise events to reduce costs. What should you do?
⚠ Common exam trap
It's easy for candidates to choose the Log Analytics agent (MMA) option because it is familiar from legacy setups, but the exam tests knowledge of the newer Azure Monitor agent (AMA) and its centralized configuration via DCRs, which is the recommended and scalable solution for modern environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the Azure Monitor agent via Azure Policy and create a data collection rule to collect Event ID 4625.
The Azure Monitor agent (AMA) is the current recommended agent for collecting security events from VMs, and using Azure Policy to deploy it ensures centralized, scalable configuration across 500 VMs. A data collection rule (DCR) can be configured to collect only Event ID 4625, filtering out high-volume noise events at the source, which reduces costs by minimizing data ingestion into the Log Analytics workspace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable VM Insights on all VMs and use the Performance view to detect failed logons.
Why it's wrong here
VM Insights Performance view is designed to display host metrics like CPU, memory, disk, and network utilization, not security audit events. Failed logon records are Windows Security log events (Event ID 4625), which are not collected by VM Insights' performance counters. Consequently, this approach would not surface the required data, and even if VM Insights were enabled, it would need a separate data collection rule for security event logs.
- ✗
Stream events to Azure Event Hubs and use a function to filter and send to Log Analytics.
Why it's wrong here
Streaming via Event Hubs with a function introduces an unnecessary intermediary processing layer that adds latency and operational overhead, whereas the scenario requires a direct, scalable ingestion path that Azure Monitor’s Data Collection Rules (DCRs) provide natively for security event collection. This option is tempting because Event Hubs excels at high-throughput, real-time event ingestion for downstream analytics or alerting, and would be correct if the requirement were to route logs to multiple destinations or perform complex transformations before storage.
- ✗
Install the Log Analytics agent on each VM and configure Windows Event log collection in the workspace.
Why it's wrong here
The legacy Log Analytics agent (Microsoft Monitoring Agent) is deprecated and cannot filter security events at the source; workspace settings force it to forward entire event logs unless you later filter in Log Analytics queries. Manually installing this agent on every VM in a fleet of five is operationally heavy and inconsistent, whereas Azure Policy enables automated, uniform deployment. Given its retirement timeline, this approach is not a durable architecture for collecting failed logon events.
- ✓
Deploy the Azure Monitor agent via Azure Policy and create a data collection rule to collect Event ID 4625.
Why this is correct
This is the correct, future-ready approach because Azure Monitor agent (AMA) is designed to collect Windows Security events and supports fine-grained XPath filtering in Data Collection Rules (DCRs) to ingest only Event ID 4625. Using Azure Policy ensures the agent is automatically deployed to every VM with consistent configuration, and the DCR can be applied at scale across subscriptions. This avoids manual installation and reduces data costs by filtering noise before it reaches the workspace, while still providing centralized control over the data collection pipeline.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.