AZ-802 Practice Question: Monitor and Troubleshoot Windows Server Environments
You are transitioning several Windows Server 2022 Azure Virtual Machines from the legacy Log Analytics Agent to the newer Azure Monitor Agent (AMA). You need to ensure that specific System and Application event logs are centralized in a Log Analytics workspace. What component must you create and associate with the virtual machines to facilitate this data collection?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Collection Rules
The Azure Monitor Agent relies on Data Collection Rules (DCR) to define which data should be collected and where it should be sent. Unlike the legacy agent which used workspace-wide settings, DCRs provide a more granular and flexible approach, allowing administrators to target specific servers with unique logging requirements while maintaining a centralized management structure in the Azure portal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Diagnostic Settings
Why it's wrong here
These settings are primarily used to export platform-level metrics and logs from Azure resources to various destinations. While they are useful for monitoring the health of the underlying infrastructure, they do not manage the internal Windows Event Log collection process handled by the Azure Monitor Agent on the guest operating system itself.
- ✗
Log Analytics Gateway
Why it's wrong here
This component acts as a proxy for servers that do not have direct internet access to reach Azure Monitor. While it facilitates communication in restricted network environments, it does not define the logic or rules for which specific event logs are collected from the Windows Server environment during the migration process.
- ✓
Data Collection Rules
Why this is correct
These rules define the data sources and destinations for the Azure Monitor Agent. By creating a rule, you specify exactly which event logs to capture and link it to the target virtual machines. This is the mandatory mechanism for configuring the AMA to stream Windows Server logs to a workspace.
- ✗
Automation Accounts
Why it's wrong here
These accounts are used for automating management tasks and orchestrating updates through tools like Update Management. They do not govern the ingestion of performance counters or event logs into Log Analytics, which is strictly the responsibility of the monitoring agent and its associated configuration rules in the modern architecture.
About these practice questions
This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.