Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an Azure subscription that contains hundreds of Azure virtual machines running Windows Server and Ubuntu Linux. You need to collect Windows Firewall events, Linux authpriv Syslog messages, and the Bytes Total/sec network performance counter. The counter must be sampled every 15 seconds on Windows VMs and every 60 seconds on Linux VMs. New virtual machines must be onboarded automatically. Which solution uses the minimum number of data collection rules (DCRs)?
Create two DCRs per virtual machine-one for events and one for performance counters-and associate each rule with the VM's resource ID.
Create one DCR for Windows VMs and one DCR for Linux VMs, each associated with a dynamic resource group.
Create one DCR for all event logs and a second DCR for all performance counters, and assign both to every virtual machine.
Create one DCR that includes individual performance-counter definitions with the required sampling frequencies and an Azure Resource Graph-based scope that targets every virtual machine.
A single DCR can contain multiple data-source sections. You can add two separate performance-counter entries-one for Windows set to a 15-second sampling frequency and one for Linux set to 60 seconds-together with Windows Event Log and Syslog sources. When the DCR is associated with a dynamic Azure Resource Graph query that targets all virtual-machine resources, any current or future VM receives the rule automatically. Therefore only one DCR is required. Creating separate DCRs per operating system, per data type, or per VM adds unnecessary complexity and exceeds the minimum count.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Data Collection Rule (DCR) in Azure?
Open an interactive chat with Bash
How does Azure Resource Graph help with dynamic resource targeting?
Open an interactive chat with Bash
Why is using one DCR more efficient than multiple DCRs for this scenario?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .