AZ-500 Secure compute, storage, and databases Practice Question
Your company is migrating a legacy on-premises application to Azure VMs. The application writes log files to a local folder. You need to collect these logs centrally for security analysis using Microsoft Sentinel. The application runs on Windows Server 2022 and is expected to generate about 50 GB of logs per day. The security team requires that logs be encrypted at rest and in transit, and that log collection has minimal latency. You set up Azure Monitor Agent (AMA) on the VM and configure a Data Collection Rule (DCR) to stream custom logs to a Log Analytics workspace. However, after 24 hours, no custom logs appear in the workspace. The AMA is reporting as healthy. You need to troubleshoot and resolve the issue. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The DCR does not include the correct table name for the custom log, or the table does not exist in the Log Analytics workspace.
The DCR must reference the custom log table created in the Log Analytics workspace; if the table name does not match or the table does not exist, logs will not be ingested. Option B: AMA can collect custom logs from a local file path; the path does not need to be a network share. Option C: The log file format is not limited to JSON; AMA can collect plain text logs with a defined pattern. Option D: The agent does not require local admin privileges for custom log collection; it runs as Local System.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The DCR does not include the correct table name for the custom log, or the table does not exist in the Log Analytics workspace.
Why this is correct
The Data Collection Rule (DCR) must map the incoming stream to an existing table in the Log Analytics workspace, typically a custom table with a `_CL` suffix. The `tableName` specified in the `destinations` section must exactly match the table that was created, including case and suffix. The DCR does not automatically create the table, so if the name is misspelled or the table has not been provisioned, the ingestion pipeline silently drops the data.
- ✗
The custom log file path specified in the DCR is a local path, but AMA requires a network share for custom log collection.
Why it's wrong here
Azure Monitor Agent can readily collect custom logs from local file paths, both on Windows (e.g., `C:\Logs\*.log`) and Linux (e.g., `/var/log/*.log`). Network shares are not required—and often not recommended—because they add permission and reliability complexity. A local path in the DCR is perfectly valid, so this is not the cause of a failed ingestion.
- ✗
The log file format is not JSON, but AMA only supports custom logs in JSON format.
Why it's wrong here
Azure Monitor Agent's custom log collection supports multiple formats, not just JSON. While JSON with newline-delimited records is one supported layout, the agent also handles plain-text files that follow a defined pattern specified in the DCR's `transformKql` or delimited by a custom separator. The presence of non-JSON logs is therefore not inherently an issue, as long as the transformation logic correctly parses the record boundaries.
- ✗
The VM does not have local administrator privileges required for the AMA to read the log files.
Why it's wrong here
The Azure Monitor Agent service runs under the `LocalSystem` account on Windows and as `root` or with equivalent privileges on many Linux hosts, giving it the file-system access needed to read local logs. Therefore, the VM administrator account's privileges are not directly relevant to the agent's ability to open log files. A lack of local administrator rights for the user who configures the DCR would not prevent the agent from collecting the logs, so this option is not a valid explanation for the failure.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.