Courseiva
Monitor and Maintain Azure ResourceseasyMultiple ChoiceObjective-mapped

AZ-104 Monitor and Maintain Azure Resources Practice Question

In Log Analytics, you need to find AzureActivity records for VM stop or deallocate operations from the last 24 hours. Which query should you use?

⚠ Common exam trap

Many candidates confuse the `has_any` operator with `contains` or `in`, or forget to include the time filter, leading them to select options that either don't filter by operation type or don't restrict the time window.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AzureActivity | where TimeGenerated > ago(24h) | where OperationNameValue has_any ("Microsoft.Compute/virtualMachines/deallocate/action", "Microsoft.Compute/virtualMachines/powerOff/action")

It uses the `has_any` operator to filter AzureActivity records for the exact operation names corresponding to VM stop (powerOff) and deallocate actions, and it restricts the time range to the last 24 hours using `ago(24h)`. This directly matches the requirement to find VM stop or deallocate operations within the specified timeframe.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AzureActivity | where TimeGenerated > ago(24h) | where OperationNameValue has_any ("Microsoft.Compute/virtualMachines/deallocate/action", "Microsoft.Compute/virtualMachines/powerOff/action")

    Why this is correct

    This is correct because it first uses TimeGenerated > ago(24h) to restrict the result set to activity from the last day, then applies has_any on OperationNameValue to match exactly the two control-plane operations that indicate a VM stop: deallocate/action and powerOff/action. The has_any operator performs a case-insensitive substring match across a set of literals, so it reliably captures these specific operation names for the AzureActivity table.

  • AzureActivity | summarize count() by OperationNameValue

    Why it's wrong here

    This uses summarize count() by OperationNameValue to calculate the frequency of each operation type across the entire AzureActivity table. While it reveals which operation names appear most often, it neither restricts to the 24-hour window nor filters to Microsoft.Compute/virtualMachines stop-related actions, so it cannot identify the individual records or their timestamps needed for the review.

    When this WOULD be correct

    When the question asks 'How many AzureActivity records exist for each OperationNameValue?' without time or resource type filters, this query would be correct.

  • AzureActivity | where ResourceType == "Microsoft.Compute/virtualMachines" | project TimeGenerated, ResourceGroup

    Why it's wrong here

    This filters to virtual machine-related records by checking ResourceType == "Microsoft.Compute/virtualMachines" and then projects TimeGenerated and ResourceGroup. However, it omits any time constraint and does not filter for deallocate or powerOff operations, meaning it returns all activity for VMs—including starts, restarts, writes, and other operations—not just the stop events you are investigating.

    When this WOULD be correct

    This query would be correct if the question asked: 'Find all AzureActivity records for virtual machines, showing only the time generated and resource group.'

  • AzureActivity | sort by TimeGenerated asc

    Why it's wrong here

    This only sorts the AzureActivity records by TimeGenerated in ascending order. It does not apply any time-based filter, so it returns the entire historical backlog of all activity log entries, nor does it filter by OperationNameValue or ResourceType. As a result, it cannot isolate the VM deallocate/powerOff events from the last 24 hours that the investigation requires.

    When this WOULD be correct

    This query would be correct if the question asked: 'You need to list all AzureActivity records in chronological order from oldest to newest.'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

AzureActivity | where TimeGenerated > ago(24h) | where OperationNameValue has_any ("Microsoft.Compute/virtualMachines/deallocate/action", "Microsoft.Compute/virtualMachines/powerOff/action")Correct answer

Why this is correct

This is correct because it first uses TimeGenerated > ago(24h) to restrict the result set to activity from the last day, then applies has_any on OperationNameValue to match exactly the two control-plane operations that indicate a VM stop: deallocate/action and powerOff/action. The has_any operator performs a case-insensitive substring match across a set of literals, so it reliably captures these specific operation names for the AzureActivity table.

AzureActivity | summarize count() by OperationNameValueWrong answer — click to see why

Why this is wrong here

This query summarizes the count of all operations but does not filter for VM stop/deallocate operations or the last 24 hours, so it fails to meet the question's requirements.

★ When this WOULD be the correct answer

When the question asks 'How many AzureActivity records exist for each OperationNameValue?' without time or resource type filters, this query would be correct.

Why candidates choose this

Candidates may think summarizing counts is a quick way to see operations, but they overlook the specific filtering needed for time and operation type.

AzureActivity | where ResourceType == "Microsoft.Compute/virtualMachines" | project TimeGenerated, ResourceGroupWrong answer — click to see why

Why this is wrong here

This query filters by ResourceType but does not filter by time (last 24 hours) or by specific operations (stop/deallocate), so it returns all VM records regardless of time or operation, not meeting the requirement.

★ When this WOULD be the correct answer

This query would be correct if the question asked: 'Find all AzureActivity records for virtual machines, showing only the time generated and resource group.'

Why candidates choose this

Candidates may think filtering by ResourceType is sufficient and overlook the need for time and operation filters, or they may confuse 'project' with filtering operations.

AzureActivity | sort by TimeGenerated ascWrong answer — click to see why

Why this is wrong here

This query only sorts records by TimeGenerated in ascending order without filtering for the last 24 hours or specific VM stop/deallocate operations, so it returns all AzureActivity records sorted by time, not the required subset.

★ When this WOULD be the correct answer

This query would be correct if the question asked: 'You need to list all AzureActivity records in chronological order from oldest to newest.'

Why candidates choose this

Candidates may think sorting by time is necessary to find recent events, but they overlook the need for time filtering and operation-specific filtering.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.