Microsoft AZ-104 Azure Monitor Practice Test

 

Topic 18 focuses on Azure Monitor Metrics, Logs, Alerts, and Insights for the Microsoft Certified: Azure Administrator Associate certification and the AZ-104 exam, using Microsoft Azure administration scenarios. For broader exam preparation, review the Microsoft Azure Administrator AZ-104 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

To analyze near-real-time resource performance and create threshold-based monitoring, which Azure configuration should be selected?

  1. Metric alert
  2. Azure Monitor metric
  3. Storage insights
  4. Alert processing rule

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure Monitor metric is a time-series numeric value collected for a resource or platform condition. It directly supports the requirement to analyze near-real-time resource performance and create threshold-based monitoring.

Incorrect Answers

Answer A is incorrect because Metric alert is used to notify when resource performance or platform metrics cross a defined condition; it does not provide the capability described in the scenario.

Answer C is incorrect because Storage insights is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it does not provide the capability described in the scenario.

Answer D is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.

 

Question 2

For Azure Monitor metric, which administrative outcome is expected?

  1. Review network-resource monitoring data through a consolidated experience
  2. Analyze near-real-time resource performance and create threshold-based monitoring
  3. Filter, aggregate, correlate, and summarize collected log records
  4. Detect a monitoring condition automatically instead of relying on manual dashboard review

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure Monitor metric is a time-series numeric value collected for a resource or platform condition. Its intended administrative use is to analyze near-real-time resource performance and create threshold-based monitoring.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Network insights, which is used to review network-resource monitoring data through a consolidated experience; it is not the primary purpose of Azure Monitor metric.

Answer C is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Azure Monitor metric.

Answer D is incorrect because that outcome belongs to Alert rule, which is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it is not the primary purpose of Azure Monitor metric.

 

Question 3

To audit who or what changed Azure resources at the management plane, which Azure configuration should be selected?

  1. Alert rule
  2. Azure Activity Log
  3. Network insights
  4. Kusto Query Language (KQL)

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure Activity Log is the subscription-level platform log that records control-plane events such as resource creation, updates, and administrative operations. It directly supports the requirement to audit who or what changed Azure resources at the management plane.

Incorrect Answers

Answer A is incorrect because Alert rule is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it does not provide the capability described in the scenario.

Answer C is incorrect because Network insights is used to review network-resource monitoring data through a consolidated experience; it does not provide the capability described in the scenario.

Answer D is incorrect because Kusto Query Language (KQL) is used to filter, aggregate, correlate, and summarize collected log records; it does not provide the capability described in the scenario.

 

Question 4

For Azure Activity Log, which administrative outcome is expected?

  1. Centralize operational logs and make them available for KQL analysis
  2. Analyze detailed operations inside a service beyond the subscription Activity Log
  3. Control how already-generated alerts are processed without changing every underlying alert rule
  4. Audit who or what changed Azure resources at the management plane

Correct Answer: D

 

Correct Answer

Answer D is correct because Azure Activity Log is the subscription-level platform log that records control-plane events such as resource creation, updates, and administrative operations. Its intended administrative use is to audit who or what changed Azure resources at the management plane.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Azure Activity Log.

Answer B is incorrect because that outcome belongs to Resource log, which is used to analyze detailed operations inside a service beyond the subscription Activity Log; it is not the primary purpose of Azure Activity Log.

Answer C is incorrect because that outcome belongs to Alert processing rule, which is used to control how already-generated alerts are processed without changing every underlying alert rule; it is not the primary purpose of Azure Activity Log.

 

Question 5

To analyze detailed operations inside a service beyond the subscription Activity Log, which Azure configuration should be selected?

  1. Action group
  2. Resource log
  3. Data collection rule (DCR)
  4. Log search alert

Correct Answer: B

 

Correct Answer

Answer B is correct because Resource log is service-specific diagnostic telemetry produced by an Azure resource when the relevant log category is enabled. It directly supports the requirement to analyze detailed operations inside a service beyond the subscription Activity Log.

Incorrect Answers

Answer A is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.

Answer C is incorrect because Data collection rule (DCR) is used to control collection of VM and other supported telemetry with centralized data-collection configuration; it does not provide the capability described in the scenario.

Answer D is incorrect because Log search alert is used to detect conditions that require querying collected log records rather than a single platform metric; it does not provide the capability described in the scenario.

 

Question 6

For Resource log, which administrative outcome is expected?

  1. Analyze storage availability, transactions, capacity, and related telemetry across accounts
  2. Analyze near-real-time resource performance and create threshold-based monitoring
  3. Analyze detailed operations inside a service beyond the subscription Activity Log
  4. Control how already-generated alerts are processed without changing every underlying alert rule

Correct Answer: C

 

Correct Answer

Answer C is correct because Resource log is service-specific diagnostic telemetry produced by an Azure resource when the relevant log category is enabled. Its intended administrative use is to analyze detailed operations inside a service beyond the subscription Activity Log.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Storage insights, which is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it is not the primary purpose of Resource log.

Answer B is incorrect because that outcome belongs to Azure Monitor metric, which is used to analyze near-real-time resource performance and create threshold-based monitoring; it is not the primary purpose of Resource log.

Answer D is incorrect because that outcome belongs to Alert processing rule, which is used to control how already-generated alerts are processed without changing every underlying alert rule; it is not the primary purpose of Resource log.

 

Question 7

To retain and centralize resource telemetry for analysis or downstream processing, which Azure configuration should be selected?

  1. Diagnostic setting
  2. Resource log
  3. Azure Activity Log
  4. Alert processing rule

Correct Answer: A

 

Correct Answer

Answer A is correct because Diagnostic setting is the Azure Monitor configuration that routes supported platform logs and metrics to destinations such as Log Analytics, storage, or Event Hubs. It directly supports the requirement to retain and centralize resource telemetry for analysis or downstream processing.

Incorrect Answers

Answer B is incorrect because Resource log is used to analyze detailed operations inside a service beyond the subscription Activity Log; it does not provide the capability described in the scenario.

Answer C is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.

Answer D is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.

 

Question 8

For Diagnostic setting, which administrative outcome is expected?

  1. Control how already-generated alerts are processed without changing every underlying alert rule
  2. Filter, aggregate, correlate, and summarize collected log records
  3. Retain and centralize resource telemetry for analysis or downstream processing
  4. Detect conditions that require querying collected log records rather than a single platform metric

Correct Answer: C

 

Correct Answer

Answer C is correct because Diagnostic setting is the Azure Monitor configuration that routes supported platform logs and metrics to destinations such as Log Analytics, storage, or Event Hubs. Its intended administrative use is to retain and centralize resource telemetry for analysis or downstream processing.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Alert processing rule, which is used to control how already-generated alerts are processed without changing every underlying alert rule; it is not the primary purpose of Diagnostic setting.

Answer B is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Diagnostic setting.

Answer D is incorrect because that outcome belongs to Log search alert, which is used to detect conditions that require querying collected log records rather than a single platform metric; it is not the primary purpose of Diagnostic setting.

 

Question 9

To centralize operational logs and make them available for KQL analysis, which Azure configuration should be selected?

  1. Action group
  2. Azure Activity Log
  3. Log Analytics workspace
  4. Kusto Query Language (KQL)

Correct Answer: C

 

Correct Answer

Answer C is correct because Log Analytics workspace is the Azure Monitor data store used to collect and query log data. It directly supports the requirement to centralize operational logs and make them available for KQL analysis.

Incorrect Answers

Answer A is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.

Answer B is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.

Answer D is incorrect because Kusto Query Language (KQL) is used to filter, aggregate, correlate, and summarize collected log records; it does not provide the capability described in the scenario.

 

Question 10

For Log Analytics workspace, which administrative outcome is expected?

  1. Send email, SMS, webhook, automation, or other supported responses when an alert fires
  2. Centralize operational logs and make them available for KQL analysis
  3. Retain and centralize resource telemetry for analysis or downstream processing
  4. Analyze detailed operations inside a service beyond the subscription Activity Log

Correct Answer: B

 

Correct Answer

Answer B is correct because Log Analytics workspace is the Azure Monitor data store used to collect and query log data. Its intended administrative use is to centralize operational logs and make them available for KQL analysis.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of Log Analytics workspace.

Answer C is incorrect because that outcome belongs to Diagnostic setting, which is used to retain and centralize resource telemetry for analysis or downstream processing; it is not the primary purpose of Log Analytics workspace.

Answer D is incorrect because that outcome belongs to Resource log, which is used to analyze detailed operations inside a service beyond the subscription Activity Log; it is not the primary purpose of Log Analytics workspace.

 

Question 11

To filter, aggregate, correlate, and summarize collected log records, which Azure configuration should be selected?

  1. Resource log
  2. Azure Activity Log
  3. Kusto Query Language (KQL)
  4. Log Analytics workspace

Correct Answer: C

 

Correct Answer

Answer C is correct because Kusto Query Language (KQL) is the query language used to search and analyze data in Azure Monitor Logs and Log Analytics. It directly supports the requirement to filter, aggregate, correlate, and summarize collected log records.

Incorrect Answers

Answer A is incorrect because Resource log is used to analyze detailed operations inside a service beyond the subscription Activity Log; it does not provide the capability described in the scenario.

Answer B is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.

Answer D is incorrect because Log Analytics workspace is used to centralize operational logs and make them available for KQL analysis; it does not provide the capability described in the scenario.

 

Question 12

For Kusto Query Language (KQL), which administrative outcome is expected?

  1. Send email, SMS, webhook, automation, or other supported responses when an alert fires
  2. Analyze detailed operations inside a service beyond the subscription Activity Log
  3. Monitor VM health, performance, and selected dependency information with a purpose-built view
  4. Filter, aggregate, correlate, and summarize collected log records

Correct Answer: D

 

Correct Answer

Answer D is correct because Kusto Query Language (KQL) is the query language used to search and analyze data in Azure Monitor Logs and Log Analytics. Its intended administrative use is to filter, aggregate, correlate, and summarize collected log records.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of Kusto Query Language (KQL).

Answer B is incorrect because that outcome belongs to Resource log, which is used to analyze detailed operations inside a service beyond the subscription Activity Log; it is not the primary purpose of Kusto Query Language (KQL).

Answer C is incorrect because that outcome belongs to VM Insights, which is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it is not the primary purpose of Kusto Query Language (KQL).

 

Question 13

To detect a monitoring condition automatically instead of relying on manual dashboard review, which Azure configuration should be selected?

  1. Alert processing rule
  2. VM Insights
  3. Azure Activity Log
  4. Alert rule

Correct Answer: D

 

Correct Answer

Answer D is correct because Alert rule is the Azure Monitor definition that evaluates a signal and opens an alert when configured conditions are met. It directly supports the requirement to detect a monitoring condition automatically instead of relying on manual dashboard review.

Incorrect Answers

Answer A is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.

Answer B is incorrect because VM Insights is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it does not provide the capability described in the scenario.

Answer C is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.

 

Question 14

For Alert rule, which administrative outcome is expected?

  1. Centralize operational logs and make them available for KQL analysis
  2. Audit who or what changed Azure resources at the management plane
  3. Detect a monitoring condition automatically instead of relying on manual dashboard review
  4. Filter, aggregate, correlate, and summarize collected log records

Correct Answer: C

 

Correct Answer

Answer C is correct because Alert rule is the Azure Monitor definition that evaluates a signal and opens an alert when configured conditions are met. Its intended administrative use is to detect a monitoring condition automatically instead of relying on manual dashboard review.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Alert rule.

Answer B is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of Alert rule.

Answer D is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Alert rule.

 

Question 15

To send email, SMS, webhook, automation, or other supported responses when an alert fires, which Azure configuration should be selected?

  1. Metric alert
  2. Action group
  3. Diagnostic setting
  4. Storage insights

Correct Answer: B

 

Correct Answer

Answer B is correct because Action group is a reusable Azure Monitor collection of notification and automation actions triggered by alerts. It directly supports the requirement to send email, SMS, webhook, automation, or other supported responses when an alert fires.

Incorrect Answers

Answer A is incorrect because Metric alert is used to notify when resource performance or platform metrics cross a defined condition; it does not provide the capability described in the scenario.

Answer C is incorrect because Diagnostic setting is used to retain and centralize resource telemetry for analysis or downstream processing; it does not provide the capability described in the scenario.

Answer D is incorrect because Storage insights is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it does not provide the capability described in the scenario.

 

Question 16

For Action group, which administrative outcome is expected?

  1. Filter, aggregate, correlate, and summarize collected log records
  2. Centralize operational logs and make them available for KQL analysis
  3. Audit who or what changed Azure resources at the management plane
  4. Send email, SMS, webhook, automation, or other supported responses when an alert fires

Correct Answer: D

 

Correct Answer

Answer D is correct because Action group is a reusable Azure Monitor collection of notification and automation actions triggered by alerts. Its intended administrative use is to send email, SMS, webhook, automation, or other supported responses when an alert fires.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Action group.

Answer B is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Action group.

Answer C is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of Action group.

 

Question 17

To control how already-generated alerts are processed without changing every underlying alert rule, which Azure configuration should be selected?

  1. Alert processing rule
  2. Azure Activity Log
  3. VM Insights
  4. Log search alert

Correct Answer: A

 

Correct Answer

Answer A is correct because Alert processing rule is a rule that modifies alert notification behavior, such as suppressing actions during maintenance. It directly supports the requirement to control how already-generated alerts are processed without changing every underlying alert rule.

Incorrect Answers

Answer B is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.

Answer C is incorrect because VM Insights is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it does not provide the capability described in the scenario.

Answer D is incorrect because Log search alert is used to detect conditions that require querying collected log records rather than a single platform metric; it does not provide the capability described in the scenario.

 

Question 18

For Alert processing rule, which administrative outcome is expected?

  1. Control how already-generated alerts are processed without changing every underlying alert rule
  2. Send email, SMS, webhook, automation, or other supported responses when an alert fires
  3. Filter, aggregate, correlate, and summarize collected log records
  4. Analyze detailed operations inside a service beyond the subscription Activity Log

Correct Answer: A

 

Correct Answer

Answer A is correct because Alert processing rule is a rule that modifies alert notification behavior, such as suppressing actions during maintenance. Its intended administrative use is to control how already-generated alerts are processed without changing every underlying alert rule.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of Alert processing rule.

Answer C is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Alert processing rule.

Answer D is incorrect because that outcome belongs to Resource log, which is used to analyze detailed operations inside a service beyond the subscription Activity Log; it is not the primary purpose of Alert processing rule.

 

Question 19

To notify when resource performance or platform metrics cross a defined condition, which Azure configuration should be selected?

  1. VM Insights
  2. Alert rule
  3. Azure Activity Log
  4. Metric alert

Correct Answer: D

 

Correct Answer

Answer D is correct because Metric alert is an Azure Monitor alert based on numeric metric time-series data. It directly supports the requirement to notify when resource performance or platform metrics cross a defined condition.

Incorrect Answers

Answer A is incorrect because VM Insights is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it does not provide the capability described in the scenario.

Answer B is incorrect because Alert rule is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it does not provide the capability described in the scenario.

Answer C is incorrect because Azure Activity Log is used to audit who or what changed Azure resources at the management plane; it does not provide the capability described in the scenario.

 

Question 20

For Metric alert, which administrative outcome is expected?

  1. Notify when resource performance or platform metrics cross a defined condition
  2. Analyze storage availability, transactions, capacity, and related telemetry across accounts
  3. Control how already-generated alerts are processed without changing every underlying alert rule
  4. Monitor VM health, performance, and selected dependency information with a purpose-built view

Correct Answer: A

 

Correct Answer

Answer A is correct because Metric alert is an Azure Monitor alert based on numeric metric time-series data. Its intended administrative use is to notify when resource performance or platform metrics cross a defined condition.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Storage insights, which is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it is not the primary purpose of Metric alert.

Answer C is incorrect because that outcome belongs to Alert processing rule, which is used to control how already-generated alerts are processed without changing every underlying alert rule; it is not the primary purpose of Metric alert.

Answer D is incorrect because that outcome belongs to VM Insights, which is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it is not the primary purpose of Metric alert.

 

Question 21

To detect conditions that require querying collected log records rather than a single platform metric, which Azure configuration should be selected?

  1. Metric alert
  2. Alert rule
  3. Storage insights
  4. Log search alert

Correct Answer: D

 

Correct Answer

Answer D is correct because Log search alert is an Azure Monitor alert that evaluates the results of a log query. It directly supports the requirement to detect conditions that require querying collected log records rather than a single platform metric.

Incorrect Answers

Answer A is incorrect because Metric alert is used to notify when resource performance or platform metrics cross a defined condition; it does not provide the capability described in the scenario.

Answer B is incorrect because Alert rule is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it does not provide the capability described in the scenario.

Answer C is incorrect because Storage insights is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it does not provide the capability described in the scenario.

 

Question 22

For Log search alert, which administrative outcome is expected?

  1. Filter, aggregate, correlate, and summarize collected log records
  2. Detect conditions that require querying collected log records rather than a single platform metric
  3. Review network-resource monitoring data through a consolidated experience
  4. Send email, SMS, webhook, automation, or other supported responses when an alert fires

Correct Answer: B

 

Correct Answer

Answer B is correct because Log search alert is an Azure Monitor alert that evaluates the results of a log query. Its intended administrative use is to detect conditions that require querying collected log records rather than a single platform metric.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Log search alert.

Answer C is incorrect because that outcome belongs to Network insights, which is used to review network-resource monitoring data through a consolidated experience; it is not the primary purpose of Log search alert.

Answer D is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of Log search alert.

 

Question 23

To monitor VM health, performance, and selected dependency information with a purpose-built view, which Azure configuration should be selected?

  1. VM Insights
  2. Metric alert
  3. Alert processing rule
  4. Storage insights

Correct Answer: A

 

Correct Answer

Answer A is correct because VM Insights is an Azure Monitor experience that provides performance and dependency visibility for virtual machines. It directly supports the requirement to monitor VM health, performance, and selected dependency information with a purpose-built view.

Incorrect Answers

Answer B is incorrect because Metric alert is used to notify when resource performance or platform metrics cross a defined condition; it does not provide the capability described in the scenario.

Answer C is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.

Answer D is incorrect because Storage insights is used to analyze storage availability, transactions, capacity, and related telemetry across accounts; it does not provide the capability described in the scenario.

 

Question 24

For VM Insights, which administrative outcome is expected?

  1. Monitor VM health, performance, and selected dependency information with a purpose-built view
  2. Send email, SMS, webhook, automation, or other supported responses when an alert fires
  3. Audit who or what changed Azure resources at the management plane
  4. Analyze near-real-time resource performance and create threshold-based monitoring

Correct Answer: A

 

Correct Answer

Answer A is correct because VM Insights is an Azure Monitor experience that provides performance and dependency visibility for virtual machines. Its intended administrative use is to monitor VM health, performance, and selected dependency information with a purpose-built view.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Action group, which is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it is not the primary purpose of VM Insights.

Answer C is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of VM Insights.

Answer D is incorrect because that outcome belongs to Azure Monitor metric, which is used to analyze near-real-time resource performance and create threshold-based monitoring; it is not the primary purpose of VM Insights.

 

Question 25

To analyze storage availability, transactions, capacity, and related telemetry across accounts, which Azure configuration should be selected?

  1. Alert rule
  2. Action group
  3. Storage insights
  4. Data collection rule (DCR)

Correct Answer: C

 

Correct Answer

Answer C is correct because Storage insights is an Azure Monitor workbook-based experience for viewing storage-account health and performance indicators. It directly supports the requirement to analyze storage availability, transactions, capacity, and related telemetry across accounts.

Incorrect Answers

Answer A is incorrect because Alert rule is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it does not provide the capability described in the scenario.

Answer B is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.

Answer D is incorrect because Data collection rule (DCR) is used to control collection of VM and other supported telemetry with centralized data-collection configuration; it does not provide the capability described in the scenario.

 

Question 26

For Storage insights, which administrative outcome is expected?

  1. Monitor VM health, performance, and selected dependency information with a purpose-built view
  2. Audit who or what changed Azure resources at the management plane
  3. Analyze storage availability, transactions, capacity, and related telemetry across accounts
  4. Filter, aggregate, correlate, and summarize collected log records

Correct Answer: C

 

Correct Answer

Answer C is correct because Storage insights is an Azure Monitor workbook-based experience for viewing storage-account health and performance indicators. Its intended administrative use is to analyze storage availability, transactions, capacity, and related telemetry across accounts.

Incorrect Answers

Answer A is incorrect because that outcome belongs to VM Insights, which is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it is not the primary purpose of Storage insights.

Answer B is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of Storage insights.

Answer D is incorrect because that outcome belongs to Kusto Query Language (KQL), which is used to filter, aggregate, correlate, and summarize collected log records; it is not the primary purpose of Storage insights.

 

Question 27

To review network-resource monitoring data through a consolidated experience, which Azure configuration should be selected?

  1. Alert processing rule
  2. Action group
  3. Log Analytics workspace
  4. Network insights

Correct Answer: D

 

Correct Answer

Answer D is correct because Network insights is an Azure Monitor experience that surfaces health and monitoring information for Azure networking resources. It directly supports the requirement to review network-resource monitoring data through a consolidated experience.

Incorrect Answers

Answer A is incorrect because Alert processing rule is used to control how already-generated alerts are processed without changing every underlying alert rule; it does not provide the capability described in the scenario.

Answer B is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.

Answer C is incorrect because Log Analytics workspace is used to centralize operational logs and make them available for KQL analysis; it does not provide the capability described in the scenario.

 

Question 28

For Network insights, which administrative outcome is expected?

  1. Review network-resource monitoring data through a consolidated experience
  2. Centralize operational logs and make them available for KQL analysis
  3. Audit who or what changed Azure resources at the management plane
  4. Detect conditions that require querying collected log records rather than a single platform metric

Correct Answer: A

 

Correct Answer

Answer A is correct because Network insights is an Azure Monitor experience that surfaces health and monitoring information for Azure networking resources. Its intended administrative use is to review network-resource monitoring data through a consolidated experience.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Network insights.

Answer C is incorrect because that outcome belongs to Azure Activity Log, which is used to audit who or what changed Azure resources at the management plane; it is not the primary purpose of Network insights.

Answer D is incorrect because that outcome belongs to Log search alert, which is used to detect conditions that require querying collected log records rather than a single platform metric; it is not the primary purpose of Network insights.

 

Question 29

To control collection of VM and other supported telemetry with centralized data-collection configuration, which Azure configuration should be selected?

  1. Data collection rule (DCR)
  2. Network insights
  3. Kusto Query Language (KQL)
  4. Action group

Correct Answer: A

 

Correct Answer

Answer A is correct because Data collection rule (DCR) is an Azure Monitor rule that defines how supported monitoring data is collected, transformed, and routed by modern monitoring agents and pipelines. It directly supports the requirement to control collection of VM and other supported telemetry with centralized data-collection configuration.

Incorrect Answers

Answer B is incorrect because Network insights is used to review network-resource monitoring data through a consolidated experience; it does not provide the capability described in the scenario.

Answer C is incorrect because Kusto Query Language (KQL) is used to filter, aggregate, correlate, and summarize collected log records; it does not provide the capability described in the scenario.

Answer D is incorrect because Action group is used to send email, SMS, webhook, automation, or other supported responses when an alert fires; it does not provide the capability described in the scenario.

 

Question 30

For Data collection rule (DCR), which administrative outcome is expected?

  1. Monitor VM health, performance, and selected dependency information with a purpose-built view
  2. Control collection of VM and other supported telemetry with centralized data-collection configuration
  3. Detect a monitoring condition automatically instead of relying on manual dashboard review
  4. Centralize operational logs and make them available for KQL analysis

Correct Answer: B

 

Correct Answer

Answer B is correct because Data collection rule (DCR) is an Azure Monitor rule that defines how supported monitoring data is collected, transformed, and routed by modern monitoring agents and pipelines. Its intended administrative use is to control collection of VM and other supported telemetry with centralized data-collection configuration.

Incorrect Answers

Answer A is incorrect because that outcome belongs to VM Insights, which is used to monitor VM health, performance, and selected dependency information with a purpose-built view; it is not the primary purpose of Data collection rule (DCR).

Answer C is incorrect because that outcome belongs to Alert rule, which is used to detect a monitoring condition automatically instead of relying on manual dashboard review; it is not the primary purpose of Data collection rule (DCR).

Answer D is incorrect because that outcome belongs to Log Analytics workspace, which is used to centralize operational logs and make them available for KQL analysis; it is not the primary purpose of Data collection rule (DCR).

 

img