Drag a concept onto its matching description — or click a concept then click the description.
Log Analytics workspace
Storage account
Event Hub
Action group
An operations lead must choose the right Azure Monitor target for each requirement. Match each requirement to the Azure component that best satisfies it.
Drag a concept onto its matching description — or click a concept then click the description.
Log Analytics workspace
Storage account
Event Hub
Action group
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Metrics Explorer: Shows real-time metrics
Metrics Explorer shows real-time metrics; Action Groups define notification actions; Log Analytics Workspace stores and queries logs; Alert Rules define conditions; Workbooks provide visualizations.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Metrics Explorer: Shows real-time metrics
Why this is correct
Metrics Explorer is the primary Azure Monitor tool for visualizing near real-time performance metrics from Azure resources. It allows you to query, chart, and compare metrics, applying filters, splitting, and aggregation to diagnose live availability and performance issues. This makes it the correct choice for viewing real-time metrics.
Action Groups: Define notification actions
Why this is correct
Action Groups in Azure Monitor define the notification and automation actions taken when an alert fires, such as sending email, SMS, voice calls, or triggering webhooks and ITSM tickets. They are not diagnostic tools themselves; instead, they are the delivery mechanism that alert rules invoke to operationalize a triggering condition.
Log Analytics Workspace: Provides visualizations
Why it's wrong here
This is incorrect because a Log Analytics Workspace is the repository and querying engine for Azure Monitor log data, using KQL to analyze collected logs. Visualizations are provided by Azure Monitor Workbooks, which can consume log analytics query results and display them as charts and interactive panels. The workspace itself only returns tabular query results, so it cannot be considered a visualization tool.
Alert Rules: Define conditions
Why this is correct
Alert Rules define the specific conditions that trigger an alert, such as metric thresholds, log search query results, or activity log events. Each rule includes conditions, a severity level, and an assigned action group that will be notified when the rule fires. They are the detection logic, not the response mechanism.
Workbooks: Stores and queries logs
Why it's wrong here
This is incorrect because storing and querying log data is the core function of Log Analytics Workspace, not Workbooks. Workbooks are interactive reporting documents in Azure Monitor that visualize metrics and log query results through charts, tiles, and parameterized user input, making them a presentation surface rather than a data storage back end.
Go deeper
Learn chapter
Dynamic Membership Groups
Key term
Log Analytics workspace
A Log Analytics workspace is a unique environment in Azure Monitor where log data from various sources is collected, stored, and queried for analysis and reporting.
Key term
Azure Monitor
Azure Monitor is a cloud service that collects, analyzes, and acts on telemetry data from your Azure and on-premises resources to help you understand performance and availability.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A production team wants to match common Azure Monitor components to the action each one performs. Match each item on the left to the best description on the right.
mediumWhy A: Log Analytics workspace stores logs centrally; Azure Monitor Metrics handles numeric time-series data; Application Insights focuses on application performance; Activity Log tracks control plane events; Alerts send notifications; Workbooks create interactive reports.
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.