Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-305 All Questions

View all questions & answers for the AZ-305 exam

Exam AZ-305 topic 1 question 10 discussion

Actual exam question from Microsoft's AZ-305
Question #: 10
Topic #: 1
[All AZ-305 Questions]

DRAG DROP -
You have an Azure subscription. The subscription contains Azure virtual machines that run Windows Server 2016 and Linux.
You need to use Azure Monitor to design an alerting strategy for security-related events.
Which Azure Monitor Logs tables should you query? To answer, drag the appropriate tables to the correct log types. Each table may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources-windows-events https://docs.microsoft.com/en-us/azure/azure-monitor/agents/data-sources-syslog

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Eltooth
Highly Voted 2 years, 11 months ago
Correct answer - Windows : Event. Linux : Syslog
upvoted 66 times
...
NotMeAnyWay
Highly Voted 2 months ago
To design an alerting strategy for security-related events in Azure Monitor, you should query the following Azure Monitor Logs tables: 1. SecurityEvent - This table contains security events and other system events that are generated by Windows operating systems. The table includes information about the event, such as the event ID, event source, and severity level. 2. Syslog - This table contains security-related events and other system events that are generated by Linux and other Unix-based operating systems. The table includes information about the event, such as the facility and severity level.
upvoted 20 times
...
RealmTarget
Most Recent 4 days, 13 hours ago
Remember "Event Viewer" for Windows helps me every time.
upvoted 1 times
...
SeMo0o0o0o
1 week, 6 days ago
CORRECT
upvoted 1 times
...
23169fd
2 months ago
The given answer is correct. Event: For Windows VMs, the Event table provides a structured and centralized way to collect and analyze system and application events. It’s essential for monitoring security events, such as unauthorized access attempts, system errors, and other critical events logged by the Windows Event Viewer. Syslog: For Linux VMs, Syslog provides a similar capability by capturing system and application logs. It is essential for monitoring Linux-specific events, ensuring that you can track security-related incidents like failed SSH login attempts or application-specific warnings and errors.
upvoted 1 times
...
stonwall12
1 year, 2 months ago
Correct Answer - Windows: Events For Windows logs, we'll need to query the Event table in Azure Monitor Logs. Windows event logs data are collected into the Event table when you use the Log Analytics agent. https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-sources-windows-events Correct Answer - Linux: Syslogs For Linux logs, we'll need to query the Syslog table. The Linux system logs (syslog data) are collected into the Syslog table when you use the Log Analytics agent on Linux VMs. https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-sources-syslog
upvoted 4 times
...
wdjonz
1 year, 6 months ago
Correct answer - Windows : Event. Linux : Syslog
upvoted 2 times
...
zellck
1 year, 9 months ago
1. Event 2. Syslog https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-sources-windows-events#log-queries-with-windows-events https://learn.microsoft.com/en-us/azure/azure-monitor/agents/data-sources-syslog Syslog is an event logging protocol that's common to Linux. Applications send messages that might be stored on the local machine or delivered to a Syslog collector. When the Log Analytics agent for Linux is installed, it configures the local Syslog daemon to forward messages to the agent. The agent then sends the messages to Azure Monitor where a corresponding record is created.
upvoted 2 times
...
jj22222
1 year, 9 months ago
Event and syslog
upvoted 1 times
...
OPT_001122
1 year, 10 months ago
correct Windows : Event. Linux : Syslog Thanks all you have mentioned the exam dates
upvoted 4 times
...
jj22222
1 year, 10 months ago
answer is correct
upvoted 2 times
...
Bummer_boy
1 year, 10 months ago
Event for MS events and Syslog for linux ones
upvoted 1 times
...
janvandermerwer
1 year, 10 months ago
Event and Syslog are a go. - In operating system level logging, rather than interactions with other services logging.
upvoted 1 times
...
scottishstvao
2 years, 4 months ago
The given Answer is correct.
upvoted 1 times
...
Gor
2 years, 6 months ago
Correct - Windows : Event. Linux : Syslog
upvoted 1 times
...
geobarou
2 years, 7 months ago
I think the correct answer is Azure Activity and Syslog. If you see in the first link it says: "You can't configure collection of security events from the workspace." If you check the link for Azure Activity the security is in the category. Link: https://docs.microsoft.com/en-us/azure/azure-monitor/reference/tables/azureactivity
upvoted 1 times
ele123
2 years, 3 months ago
The given answer is correct. Azure Activity is not correct, as it keeps logs about interaction with the services, for example modify the VM properties, but the events coming from the OS are into Events table.
upvoted 4 times
...
...
Teringzooi
2 years, 7 months ago
Indeed, correct!
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...