The team needs alerts for VM CPU and storage capacity thresholds, but they want to keep telemetry ingestion costs as low as possible. Which approach is best?
Metric alerts evaluate native platform metrics directly and do not require broad log ingestion, so they are usually the most cost-aware option for threshold monitoring. For CPU and capacity-type measurements that are available as metrics, this approach gives near real-time alerting with minimal telemetry overhead. It fits the requirement to monitor multiple resources while keeping data collection costs down.
Why this answer
Azure Monitor metric alerts are the most cost-effective approach because they evaluate lightweight, pre-collected platform metrics (e.g., CPU percentage, disk read/write operations) at regular intervals without ingesting or storing raw log data. This avoids the ingestion and retention costs associated with sending diagnostic logs to a Log Analytics workspace, making it ideal for simple threshold-based monitoring of VM CPU and storage capacity.
Exam trap
The trap here is that candidates often assume Log Analytics is always the right choice for alerts because it provides richer data, but they overlook the cost implications of ingesting and storing diagnostic logs for simple threshold monitoring, where metric alerts are both sufficient and far cheaper.
Why the other options are wrong
Sending all VM diagnostic logs to Log Analytics incurs significant data ingestion costs, which contradicts the goal of keeping telemetry ingestion costs low. Log search alerts also require continuous log ingestion, increasing expenses compared to metric alerts that use pre-aggregated data.
A Recovery Services vault backup policy with a short retention period does not provide alerts for VM CPU and storage capacity thresholds; it only manages backup retention, not real-time performance monitoring.
Azure Policy audits compliance but does not generate real-time alerts for CPU or storage thresholds; it only evaluates and reports configuration drift, not performance metrics.
When would these options actually be correct?
This option would be correct if the question required detailed log-based analysis (e.g., custom queries, error patterns) and cost was not a primary constraint, or if the organization already had a Log Analytics workspace with unused data capacity.
This option would be correct if the question asked for a cost-effective way to ensure VM backups are retained for a minimal duration to reduce storage costs while meeting compliance requirements.
When the requirement is to enforce compliance rules (e.g., ensuring all VMs have a specific tag or disk encryption) and audit historical configuration changes, not to alert on performance thresholds.
Why candidates pick the wrong answer
Candidates may assume that Log Analytics provides richer alerting capabilities and overlook the cost implications of ingesting all diagnostic logs, especially when the question emphasizes cost minimization.
Candidates may confuse backup policies with monitoring solutions, thinking that short retention reduces costs associated with alerting data, or they may misinterpret 'thresholds' as backup-related limits.
Candidates may confuse Azure Policy's auditing capability with monitoring and alerting, thinking policy evaluation can trigger alerts for resource utilization trends.