Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2008 R2. The domain contains 200 Windows Server 2008 R2 servers.
You need to plan a monitoring solution that meets the following requirements:
. Sends a notification by email to the administrator if an application error occurs on any of the servers
. Uses the minimum amount of administrative effort
What should you include in your plan?
A. On one server, create event subscriptions for each server. On the server, attach tasks to the application error events.
B. On one server, create an Event Trace Sessions Data Collector Set. On all servers, create a System Performance Data Collector Set.
C. On all servers, create event subscriptions for one server. On all servers, attach a task for the application error events.
D. On all servers, create a System Performance Data Collector Set. On one server, configure the report settings for the new Data Collector set.
Correct Answer: A
Explanation/Reference:
EVENT VIEWER AND TASK
The Event Viewer is a Microsoft Management Console (MMC) snap-in that enables you to browse and manage event logs including
. Application log contains events logged by applications or programs. For example, a database program might record a file error in the application log. Program developers decide which events to log.
. Security log contains events such as valid and invalid logon attempts, as well as events related to resource use, such as creating, opening, or deleting files or other objects. Administrators can specify what events are recorded in the security log. For example, if you have enabled logon auditing, attempts to log on to the system are recorded in the security log.
. Setup log contains events related to application setup.
. System log contains events logged by Windows system components. For example, the failure of a driver or other system component to load during startup is recorded in the system log. The event types logged by system components are predetermined by Windows.
. Forwarded Events log is used to store events collected from remote computers. To collect events from remote computers, you must create an event subscription.
A task can be configured to run when an event meeting specified criteria is logged.
http://technet.microsoft.com/en-us/library/cc766042.aspx