exam questions

Exam AZ-301 All Questions

View all questions & answers for the AZ-301 exam

Exam AZ-301 topic 7 question 1 discussion

Actual exam question from Microsoft's AZ-301
Question #: 1
Topic #: 7
[All AZ-301 Questions]

You need to recommend a solution for the collection of security logs for the middle tier of the payment processing system.
What should you include in the recommendation?

  • A. the Azure Log Analytics agent
  • B. Azure Event Hubs
  • C. Azure Notification Hubs
  • D. the Azure Diagnostics agent
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
References:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/diagnostics-extension-overview

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SilentH
Highly Voted 5 years ago
I believe the answer is "D" because an Azure Diagnostics agent (WAD) can send Event Logs to a storage account where it can be stored indefinitely or, this scenario's requirements, up to 7 years. The reason why "A" (Log Analytics Agent) is wrong is because it can store its Event Log data only to a Log Analytics workspace which has a max retention of 730 days (~2 years) which does not meet the 7 year retention requirement given in this scenario.
upvoted 32 times
...
AWSAzureGCPArch
Highly Voted 5 years, 3 months ago
The correct answer is "D. the Azure Diagnostics agent". Please watch this: https://azure.microsoft.com/en-us/resources/videos/security-logging-and-audit-log-collection/
upvoted 25 times
Rajuuu
5 years ago
This video makes it clear .. Answer is D.
upvoted 4 times
...
...
AKumar
Most Recent 4 years, 1 month ago
Both A and D collect logs and but given the requirement to retain the Data for 7 years, D is more likely to have an advantage over A, WAD- can be sent to Azure storage and can be retained longer period of time whereas Log analytics sent data to log analytics workspace which can retain data max for 730 days
upvoted 1 times
...
glam
4 years, 1 month ago
D. the Azure Diagnostics agent
upvoted 1 times
...
azurecert2021
4 years, 2 months ago
given answer is correct as requirement is Collect Windows security logs from all the middle-tier servers and retain the logs for a period of seven years. the Azure Log Analytics agent can only be correct answer if period is less than 730 days but here period is 7 years so only Diagnostics extension (WAD) option not sure why people is preferring Azure Log Analytics agent even if it is not fulfiling the requiremnt.. Diagnostics extension (WAD) Data collected on azure resource only Event Logs ,ETW events, Performance, File based logs ,IIS logs,.NET app logs, Crash dumps, Agent diagnostics logs. Diagnostics extension (WAD) Data sent to Azure Storage,Azure Monitor Metrics,Event Hub Log Analytics agent Data collected on azure resource,Other cloud,On-premises are Event Logs,Performance,File based logs ,IIS logs,Insights and solutions,Other services Log Analytics agent Data sent to Azure Monitor Logs
upvoted 1 times
azurecert2021
4 years, 2 months ago
Diagnostics extension (WAD) Comparison to Log Analytics agent The Log Analytics agent in Azure Monitor can also be used to collect monitoring data from the guest operating system of virtual machines. You may choose to use either or both depending on your requirements. See Overview of the Azure Monitor agents for a detailed comparison of the Azure Monitor agents. The key differences to consider are: Azure Diagnostics Extension can be used only with Azure virtual machines. The Log Analytics agent can be used with virtual machines in Azure, other clouds, and on-premises. Azure Diagnostics extension sends data to Azure Storage, Azure Monitor Metrics (Windows only) and Event Hubs. The Log Analytics agent collects data to Azure Monitor Logs. The Log Analytics agent is required for solutions, Azure Monitor for VMs, and other services such as Azure Security Center.
upvoted 1 times
...
...
chanck
4 years, 3 months ago
As per the link - https://docs.microsoft.com/en-us/azure/azure-monitor/platform/diagnostics-extension-overview#comparison-to-log-analytics-agent Comparison Diagnostic Agent to Log Analytics Agent The key differences to consider are: The Log Analytics agent is required for solutions, Azure Monitor for VMs, and other services such as Azure Security Center. I'm more incline to select (A) Log Analytics Agent as the answer
upvoted 2 times
...
rglearner
4 years, 5 months ago
7 years is the requirement for data backup retention. it is not applicable for logs. I would select diagnostics agent because it can forward data to Event Hub which is required to meet the requirement to send notification for invalid login attempts.
upvoted 1 times
...
macco455
4 years, 7 months ago
D is the answer as you can configure it to send the dat to the storage account which you can then keep for however long you want. Whereas Log Analytics you can only keep it for 730 days
upvoted 1 times
...
ChanderM
4 years, 8 months ago
Answer seems correct. In some sample questions on other site I saw it is mentioned specifically 2 year and then Log analytical work space is correct answer as it can keep for 730 days.
upvoted 3 times
...
X_L
4 years, 8 months ago
The answer phrasing is incorrect; there is no such thing as 'the Azure Diagnostics agent'. There is either a Diagnostic Extension or a Log Analytics agent.
upvoted 3 times
...
zarl
4 years, 8 months ago
The Azure Diagnostics agent should be used when you want to archive logs and metrics to Azure storage.
upvoted 1 times
...
eug45
4 years, 9 months ago
The answer is A: Here the security logs can be sent to a Log Analytics workspace. Hence the Azure Log Analytics agent needs to be installed on the virtual machines hosting the middle tier component.
upvoted 1 times
...
Prash85
4 years, 10 months ago
Host the middle tier of the payment processing system on a virtual machine. So this is a Virtual Machine... Azure Diagnostics agent is the correct one.
upvoted 2 times
...
DeveshSolanki
4 years, 10 months ago
Answer A. Azure Log Analytics agent
upvoted 1 times
...
Prash85
4 years, 10 months ago
Max retention in log analytics workspace is 730 days...requirement is 7 years of retention so Diagnostics agent
upvoted 3 times
...
blitz
4 years, 11 months ago
Correct answer i A. https://docs.microsoft.com/pl-pl/azure/azure-monitor/platform/log-analytics-agent Azure Diagnostic agent can be used only on virtual machines.
upvoted 1 times
Aresius
4 years, 9 months ago
Middle tier is hosted in a virtual machine.
upvoted 1 times
...
...
Puneetk83
4 years, 11 months ago
A Azure Diagnostics Extension can be used only with Azure virtual machines. The Log Analytics agent can be used with virtual machines in Azure, other clouds, and on-premises.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago