Courseiva

AZ-802 Practice Question: Monitor and Troubleshoot Windows Server Environments

You are transitioning several Windows Server 2022 Azure Virtual Machines from the legacy Log Analytics Agent to the newer Azure Monitor Agent (AMA). You need to ensure that specific System and Application event logs are centralized in a Log Analytics workspace. What component must you create and associate with the virtual machines to facilitate this data collection?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Collection Rules

The Azure Monitor Agent relies on Data Collection Rules (DCR) to define which data should be collected and where it should be sent. Unlike the legacy agent which used workspace-wide settings, DCRs provide a more granular and flexible approach, allowing administrators to target specific servers with unique logging requirements while maintaining a centralized management structure in the Azure portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Diagnostic Settings

    Why it's wrong here

    These settings are primarily used to export platform-level metrics and logs from Azure resources to various destinations. While they are useful for monitoring the health of the underlying infrastructure, they do not manage the internal Windows Event Log collection process handled by the Azure Monitor Agent on the guest operating system itself.

  • Log Analytics Gateway

    Why it's wrong here

    This component acts as a proxy for servers that do not have direct internet access to reach Azure Monitor. While it facilitates communication in restricted network environments, it does not define the logic or rules for which specific event logs are collected from the Windows Server environment during the migration process.

  • Data Collection Rules

    Why this is correct

    These rules define the data sources and destinations for the Azure Monitor Agent. By creating a rule, you specify exactly which event logs to capture and link it to the target virtual machines. This is the mandatory mechanism for configuring the AMA to stream Windows Server logs to a workspace.

  • Automation Accounts

    Why it's wrong here

    These accounts are used for automating management tasks and orchestrating updates through tools like Update Management. They do not govern the ingestion of performance counters or event logs into Log Analytics, which is strictly the responsibility of the monitoring agent and its associated configuration rules in the modern architecture.

About these practice questions

This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.