nerdexam
Microsoft

AZ-305 · Question #22

Drag and Drop Question You have an Azure subscription. The subscription contains Azure virtual machines that run Windows Server 2016 and Linux. You need to use Azure Monitor to design an alerting…

The correct answer is Event; Syslog. The 'Event' table in Azure Monitor Logs stores Windows Event Log data, including security events from Windows Server 2016 machines (such as those found in the Windows Security Event Log). The 'Syslog' table stores syslog data from Linux machines, which is the standard logging…

Submitted by packet_pusher· Mar 6, 2026Monitor and Maintain Azure Resources / Design and Implement Monitoring and Alerting Strategy using Azure Monitor

Question

Drag and Drop Question You have an Azure subscription. The subscription contains Azure virtual machines that run Windows Server 2016 and Linux. You need to use Azure Monitor to design an alerting strategy for security-related events. Which Azure Monitor Logs tables should you query? To answer, drag the appropriate tables to the correct log types. Each table may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-305 question #22 exhibit 1
AZ-305 question #22 exhibit 2

Answer Area

Drag items

AzureActivityAzureDiagnosticsEventSyslog

Correct arrangement

  • Event
  • Syslog

Explanation

The 'Event' table in Azure Monitor Logs stores Windows Event Log data, including security events from Windows Server 2016 machines (such as those found in the Windows Security Event Log). The 'Syslog' table stores syslog data from Linux machines, which is the standard logging mechanism for security-related events on Linux systems. Together, these two tables cover the operating system-level security event logging needs for both Windows and Linux virtual machines monitored via the Log Analytics agent.

Topics

#Azure Monitor Logs#Log Analytics Tables#Security Alerting#Windows and Linux Monitoring

Community Discussion

No community discussion yet for this question.

Full AZ-305 Practice