To investigate security events generated by a Windows Server 2016 virtual machine, which Azure Monitor capability should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: Logs.
Why this is the answer
The correct answer is Logs. Azure Monitor Logs, powered by Log Analytics, is designed to collect, index, and analyze large volumes of log data from various sources, including Windows Server VMs. Security events generated by a Windows Server 2016 VM, such as successful/failed logins, process creation, or security policy changes, are typically recorded in the Windows Event Log and can be ingested into Azure Monitor Logs for centralized analysis and alerting. Application Log is incorrect because while Windows Server has an Application Log, Azure Monitor's "Application Log" refers more specifically to application-level logs (e.g., from web apps), not the general security events of the OS. Metrics are numerical values that describe system performance or resource utilization (e.g., CPU usage, network I/O), not detailed security events. The Activity Log records control-plane events in Azure (e.g., VM creation, resource deletion), not guest-level OS security events within the VM itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed