Microsoft AZ-104 Azure Monitor Practice Test
Topic 18 focuses on Azure Monitor Metrics, Logs, Alerts, and Insights for the Microsoft Certified: Azure Administrator Associate certification and the AZ-104 exam, using Microsoft Azure administration scenarios. For broader exam preparation, review the Microsoft Azure Administrator AZ-104 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
To analyze near-real-time resource performance and create threshold-based monitoring, which Azure configuration should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Azure Monitor metric is a time-series numeric value collected for a resource or platform condition. It directly supports the requirement to analyze near-real-time resource performance and create threshold-based monitoring.
Incorrect Answers
Answer A is incorrect because Metric alert is used to notify when resource performance or platform metrics cross a defined condition; it does not provide the capability described in the scenario.
Answer C is incorrect because Storage insights is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it does not provide the capability described in the scenario.
Answer D is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.
Question 2
For Azure Monitor metric, which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because Azure Monitor metric is a time-series numeric value collected for a resource or platform condition. Its intended administrative use is to analyze near-real-time resource performance and create threshold-based monitoring.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Network insights, which is used to review network-resource monitoring data through a consolidated experience; it is not the primary purpose of Azure Monitor metric.
Answer C is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Azure Monitor metric.
Answer D is incorrect because that outcome belongs to Alert rule, which is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it is not the primary purpose of Azure Monitor metric.
Question 3
To audit who or what changed Azure resources at the management plane, which Azure configuration should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Azure Activity Log is the subscription-level platform log that records control-plane events such as resource creation, updates, and administrative operations. It directly supports the requirement to audit who or what changed Azure resources at the management plane.
Incorrect Answers
Answer A is incorrect because Alert rule is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it does not provide the capability described in the scenario.
Answer C is incorrect because Network insights is used to review network-resource monitoring data through a consolidated experience; it does not provide the capability described in the scenario.
Answer D is incorrect because Kusto Query Language (KQL) is used to filter, aggregate, correlate, and summarize collected log records; it does not provide the capability described in the scenario.
Question 4
For Azure Activity Log, which administrative outcome is expected?
Correct Answer: D
Correct Answer
Answer D is correct because Azure Activity Log is the subscription-level platform log that records control-plane events such as resource creation, updates, and administrative operations. Its intended administrative use is to audit who or what changed Azure resources at the management plane.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Azure Activity Log.
Answer B is incorrect because that outcome belongs to Resource log, which is used to analyze detailed operations inside a service beyond the subscription Activity Log; it is not the primary purpose of Azure Activity Log.
Answer C is incorrect because that outcome belongs to Alert processing rule, which is used to control how already-generated alerts are processed without changing every underlying alert rule; it is not the primary purpose of Azure Activity Log.
Question 5
To analyze detailed operations inside a service beyond the subscription Activity Log, which Azure configuration should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Resource log is service-specific diagnostic telemetry produced by an Azure resource when the relevant log category is enabled. It directly supports the requirement to analyze detailed operations inside a service beyond the subscription Activity Log.
Incorrect Answers
Answer A is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.
Answer C is incorrect because Data collection rule (DCR) is used to control collection of VM and other supported telemetry with centralized data-collection configuration; it does not provide the capability described in the scenario.
Answer D is incorrect because Log search alert is used to detect conditions that require querying collected log records rather than a single platform metric; it does not provide the capability described in the scenario.
Question 6
For Resource log, which administrative outcome is expected?
Correct Answer: C
Correct Answer
Answer C is correct because Resource log is service-specific diagnostic telemetry produced by an Azure resource when the relevant log category is enabled. Its intended administrative use is to analyze detailed operations inside a service beyond the subscription Activity Log.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Storage insights, which is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it is not the primary purpose of Resource log.
Answer B is incorrect because that outcome belongs to Azure Monitor metric, which is used to analyze near-real-time resource performance and create threshold-based monitoring; it is not the primary purpose of Resource log.
Answer D is incorrect because that outcome belongs to Alert processing rule, which is used to control how already-generated alerts are processed without changing every underlying alert rule; it is not the primary purpose of Resource log.
Question 7
To retain and centralize resource telemetry for analysis or downstream processing, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Diagnostic setting is the Azure Monitor configuration that routes supported platform logs and metrics to destinations such as Log Analytics, storage, or Event Hubs. It directly supports the requirement to retain and centralize resource telemetry for analysis or downstream processing.
Incorrect Answers
Answer B is incorrect because Resource log is used to analyze detailed operations inside a service beyond the subscription Activity Log; it does not provide the capability described in the scenario.
Answer C is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.
Answer D is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.
Question 8
For Diagnostic setting, which administrative outcome is expected?
Correct Answer: C
Correct Answer
Answer C is correct because Diagnostic setting is the Azure Monitor configuration that routes supported platform logs and metrics to destinations such as Log Analytics, storage, or Event Hubs. Its intended administrative use is to retain and centralize resource telemetry for analysis or downstream processing.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Alert processing rule, which is used to control how already-generated alerts are processed without changing every underlying alert rule; it is not the primary purpose of Diagnostic setting.
Answer B is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Diagnostic setting.
Answer D is incorrect because that outcome belongs to Log search alert, which is used to detect conditions that require querying collected log records rather than a single platform metric; it is not the primary purpose of Diagnostic setting.
Question 9
To centralize operational logs and make them available for KQL analysis, which Azure configuration should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Log Analytics workspace is the Azure Monitor data store used to collect and query log data. It directly supports the requirement to centralize operational logs and make them available for KQL analysis.
Incorrect Answers
Answer A is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.
Answer B is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.
Answer D is incorrect because Kusto Query Language (KQL) is used to filter, aggregate, correlate, and summarize collected log records; it does not provide the capability described in the scenario.
Question 10
For Log Analytics workspace, which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because Log Analytics workspace is the Azure Monitor data store used to collect and query log data. Its intended administrative use is to centralize operational logs and make them available for KQL analysis.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of Log Analytics workspace.
Answer C is incorrect because that outcome belongs to Diagnostic setting, which is used to retain and centralize resource telemetry for analysis or downstream processing; it is not the primary purpose of Log Analytics workspace.
Answer D is incorrect because that outcome belongs to Resource log, which is used to analyze detailed operations inside a service beyond the subscription Activity Log; it is not the primary purpose of Log Analytics workspace.
Question 11
To filter, aggregate, correlate, and summarize collected log records, which Azure configuration should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Kusto Query Language (KQL) is the query language used to search and analyze data in Azure Monitor Logs and Log Analytics. It directly supports the requirement to filter, aggregate, correlate, and summarize collected log records.
Incorrect Answers
Answer A is incorrect because Resource log is used to analyze detailed operations inside a service beyond the subscription Activity Log; it does not provide the capability described in the scenario.
Answer B is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.
Answer D is incorrect because Log Analytics workspace is used to centralize operational logs and make them available for KQL analysis; it does not provide the capability described in the scenario.
Question 12
For Kusto Query Language (KQL), which administrative outcome is expected?
Correct Answer: D
Correct Answer
Answer D is correct because Kusto Query Language (KQL) is the query language used to search and analyze data in Azure Monitor Logs and Log Analytics. Its intended administrative use is to filter, aggregate, correlate, and summarize collected log records.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of Kusto Query Language (KQL).
Answer B is incorrect because that outcome belongs to Resource log, which is used to analyze detailed operations inside a service beyond the subscription Activity Log; it is not the primary purpose of Kusto Query Language (KQL).
Answer C is incorrect because that outcome belongs to VM Insights, which is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it is not the primary purpose of Kusto Query Language (KQL).
Question 13
To detect a monitoring condition automatically instead of relying on manual dashboard review, which Azure configuration should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Alert rule is the Azure Monitor definition that evaluates a signal and opens an alert when configured conditions are met. It directly supports the requirement to detect a monitoring condition automatically instead of relying on manual dashboard review.
Incorrect Answers
Answer A is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.
Answer B is incorrect because VM Insights is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it does not provide the capability described in the scenario.
Answer C is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.
Question 14
For Alert rule, which administrative outcome is expected?
Correct Answer: C
Correct Answer
Answer C is correct because Alert rule is the Azure Monitor definition that evaluates a signal and opens an alert when configured conditions are met. Its intended administrative use is to detect a monitoring condition automatically instead of relying on manual dashboard review.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Alert rule.
Answer B is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of Alert rule.
Answer D is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Alert rule.
Question 15
To send email, SMS, webhook, automation, or other supported responses when an alert fires, which Azure configuration should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Action group is a reusable Azure Monitor collection of notification and automation actions triggered by alerts. It directly supports the requirement to send email, SMS, webhook, automation, or other supported responses when an alert fires.
Incorrect Answers
Answer A is incorrect because Metric alert is used to notify when resource performance or platform metrics cross a defined condition; it does not provide the capability described in the scenario.
Answer C is incorrect because Diagnostic setting is used to retain and centralize resource telemetry for analysis or downstream processing; it does not provide the capability described in the scenario.
Answer D is incorrect because Storage insights is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it does not provide the capability described in the scenario.
Question 16
For Action group, which administrative outcome is expected?
Correct Answer: D
Correct Answer
Answer D is correct because Action group is a reusable Azure Monitor collection of notification and automation actions triggered by alerts. Its intended administrative use is to send email, SMS, webhook, automation, or other supported responses when an alert fires.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Action group.
Answer B is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Action group.
Answer C is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of Action group.
Question 17
To control how already-generated alerts are processed without changing every underlying alert rule, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Alert processing rule is a rule that modifies alert notification behavior, such as suppressing actions during maintenance. It directly supports the requirement to control how already-generated alerts are processed without changing every underlying alert rule.
Incorrect Answers
Answer B is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.
Answer C is incorrect because VM Insights is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it does not provide the capability described in the scenario.
Answer D is incorrect because Log search alert is used to detect conditions that require querying collected log records rather than a single platform metric; it does not provide the capability described in the scenario.
Question 18
For Alert processing rule, which administrative outcome is expected?
Correct Answer: A
Correct Answer
Answer A is correct because Alert processing rule is a rule that modifies alert notification behavior, such as suppressing actions during maintenance. Its intended administrative use is to control how already-generated alerts are processed without changing every underlying alert rule.
Incorrect Answers
Answer B is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of Alert processing rule.
Answer C is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Alert processing rule.
Answer D is incorrect because that outcome belongs to Resource log, which is used to analyze detailed operations inside a service beyond the subscription Activity Log; it is not the primary purpose of Alert processing rule.
Question 19
To notify when resource performance or platform metrics cross a defined condition, which Azure configuration should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Metric alert is an Azure Monitor alert based on numeric metric time-series data. It directly supports the requirement to notify when resource performance or platform metrics cross a defined condition.
Incorrect Answers
Answer A is incorrect because VM Insights is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it does not provide the capability described in the scenario.
Answer B is incorrect because Alert rule is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it does not provide the capability described in the scenario.
Answer C is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.
Question 20
For Metric alert, which administrative outcome is expected?
Correct Answer: A
Correct Answer
Answer A is correct because Metric alert is an Azure Monitor alert based on numeric metric time-series data. Its intended administrative use is to notify when resource performance or platform metrics cross a defined condition.
Incorrect Answers
Answer B is incorrect because that outcome belongs to Storage insights, which is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it is not the primary purpose of Metric alert.
Answer C is incorrect because that outcome belongs to Alert processing rule, which is used to control how already-generated alerts are processed without changing every underlying alert rule; it is not the primary purpose of Metric alert.
Answer D is incorrect because that outcome belongs to VM Insights, which is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it is not the primary purpose of Metric alert.
Question 21
To detect conditions that require querying collected log records rather than a single platform metric, which Azure configuration should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Log search alert is an Azure Monitor alert that evaluates the results of a log query. It directly supports the requirement to detect conditions that require querying collected log records rather than a single platform metric.
Incorrect Answers
Answer A is incorrect because Metric alert is used to notify when resource performance or platform metrics cross a defined condition; it does not provide the capability described in the scenario.
Answer B is incorrect because Alert rule is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it does not provide the capability described in the scenario.
Answer C is incorrect because Storage insights is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it does not provide the capability described in the scenario.
Question 22
For Log search alert, which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because Log search alert is an Azure Monitor alert that evaluates the results of a log query. Its intended administrative use is to detect conditions that require querying collected log records rather than a single platform metric.
Incorrect Answers
Answer A is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Log search alert.
Answer C is incorrect because that outcome belongs to Network insights, which is used to review network-resource monitoring data through a consolidated experience; it is not the primary purpose of Log search alert.
Answer D is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of Log search alert.
Question 23
To monitor VM health, performance, and selected dependency information with a purpose-built view, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because VM Insights is an Azure Monitor experience that provides performance and dependency visibility for virtual machines. It directly supports the requirement to monitor VM health, performance, and selected dependency information with a purpose-built view.
Incorrect Answers
Answer B is incorrect because Metric alert is used to notify when resource performance or platform metrics cross a defined condition; it does not provide the capability described in the scenario.
Answer C is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.
Answer D is incorrect because Storage insights is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it does not provide the capability described in the scenario.
Question 24
For VM Insights, which administrative outcome is expected?
Correct Answer: A
Correct Answer
Answer A is correct because VM Insights is an Azure Monitor experience that provides performance and dependency visibility for virtual machines. Its intended administrative use is to monitor VM health, performance, and selected dependency information with a purpose-built view.
Incorrect Answers
Answer B is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of VM Insights.
Answer C is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of VM Insights.
Answer D is incorrect because that outcome belongs to Azure Monitor metric, which is used to analyze near-real-time resource performance and create threshold-based monitoring; it is not the primary purpose of VM Insights.
Question 25
To analyze storage availability, transactions, capacity, and related telemetry across accounts, which Azure configuration should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Storage insights is an Azure Monitor workbook-based experience for viewing storage-account health and performance indicators. It directly supports the requirement to analyze storage availability, transactions, capacity, and related telemetry across accounts.
Incorrect Answers
Answer A is incorrect because Alert rule is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it does not provide the capability described in the scenario.
Answer B is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.
Answer D is incorrect because Data collection rule (DCR) is used to control collection of VM and other supported telemetry with centralized data-collection configuration; it does not provide the capability described in the scenario.
Question 26
For Storage insights, which administrative outcome is expected?
Correct Answer: C
Correct Answer
Answer C is correct because Storage insights is an Azure Monitor workbook-based experience for viewing storage-account health and performance indicators. Its intended administrative use is to analyze storage availability, transactions, capacity, and related telemetry across accounts.
Incorrect Answers
Answer A is incorrect because that outcome belongs to VM Insights, which is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it is not the primary purpose of Storage insights.
Answer B is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of Storage insights.
Answer D is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Storage insights.
Question 27
To review network-resource monitoring data through a consolidated experience, which Azure configuration should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Network insights is an Azure Monitor experience that surfaces health and monitoring information for Azure networking resources. It directly supports the requirement to review network-resource monitoring data through a consolidated experience.
Incorrect Answers
Answer A is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.
Answer B is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.
Answer C is incorrect because Log Analytics workspace is used to centralize operational logs and make them available for KQL analysis; it does not provide the capability described in the scenario.
Question 28
For Network insights, which administrative outcome is expected?
Correct Answer: A
Correct Answer
Answer A is correct because Network insights is an Azure Monitor experience that surfaces health and monitoring information for Azure networking resources. Its intended administrative use is to review network-resource monitoring data through a consolidated experience.
Incorrect Answers
Answer B is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Network insights.
Answer C is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of Network insights.
Answer D is incorrect because that outcome belongs to Log search alert, which is used to detect conditions that require querying collected log records rather than a single platform metric; it is not the primary purpose of Network insights.
Question 29
To control collection of VM and other supported telemetry with centralized data-collection configuration, which Azure configuration should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Data collection rule (DCR) is an Azure Monitor rule that defines how supported monitoring data is collected, transformed, and routed by modern monitoring agents and pipelines. It directly supports the requirement to control collection of VM and other supported telemetry with centralized data-collection configuration.
Incorrect Answers
Answer B is incorrect because Network insights is used to review network-resource monitoring data through a consolidated experience; it does not provide the capability described in the scenario.
Answer C is incorrect because Kusto Query Language (KQL) is used to filter, aggregate, correlate, and summarize collected log records; it does not provide the capability described in the scenario.
Answer D is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.
Question 30
For Data collection rule (DCR), which administrative outcome is expected?
Correct Answer: B
Correct Answer
Answer B is correct because Data collection rule (DCR) is an Azure Monitor rule that defines how supported monitoring data is collected, transformed, and routed by modern monitoring agents and pipelines. Its intended administrative use is to control collection of VM and other supported telemetry with centralized data-collection configuration.
Incorrect Answers
Answer A is incorrect because that outcome belongs to VM Insights, which is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it is not the primary purpose of Data collection rule (DCR).
Answer C is incorrect because that outcome belongs to Alert rule, which is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it is not the primary purpose of Data collection rule (DCR).
Answer D is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Data collection rule (DCR).
Popular posts
Recent Posts
