Courseiva

AZ-104 Metric alerts Practice Question

You need to send an email whenever CPU utilization on VM-Prod01 exceeds 90 percent for 15 minutes. Which Azure Monitor components should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse activity log alerts (which monitor control-plane events) with metric alerts (which monitor performance data), leading candidates to incorrectly select an activity log alert for CPU utilization monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A metric alert and an action group

A metric alert monitors a specific resource metric (like CPU utilization) and triggers when a condition (e.g., >90%) is met for a given duration (15 minutes). An action group defines the notification or remediation action (e.g., sending an email). Together, they fulfill the requirement to send an email when CPU utilization exceeds 90% for 15 minutes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A metric alert and an action group

    Why this is correct

    A metric alert detects the threshold breach and the action group sends the email notification.

  • ✗

    An activity log alert only

    Why it's wrong here

    Activity log alerts do not evaluate CPU performance metrics.

    When this WOULD be correct

    An activity log alert would be correct if the question asked to send an email when a VM is deleted or when a security rule is modified, as these are service-level events recorded in the activity log.

  • ✗

    A resource lock and Azure Advisor

    Why it's wrong here

    Neither component is used to send threshold-based operational notifications.

    When this WOULD be correct

    You need to prevent accidental deletion of a critical production VM and receive recommendations to improve its reliability and performance. In this scenario, you would configure a resource lock on the VM and use Azure Advisor to get actionable recommendations.

  • ✗

    A budget alert and a private endpoint

    Why it's wrong here

    Budget alerts monitor cost, and private endpoints provide connectivity.

    When this WOULD be correct

    You need to receive an email when spending on a subscription exceeds $500, and you must ensure that a storage account is only accessible over a private network. In that case, a budget alert and a private endpoint would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

✓A metric alert and an action groupCorrect answer▾

Why this is correct

A metric alert detects the threshold breach and the action group sends the email notification.

✗An activity log alert onlyWrong answer — click to see why▾

Why this is wrong here

An activity log alert only monitors changes to Azure resources (e.g., VM creation, deletion), not performance metrics like CPU utilization. To alert on CPU exceeding 90% for 15 minutes, you need a metric alert, not an activity log alert.

★ When this WOULD be the correct answer

An activity log alert would be correct if the question asked to send an email when a VM is deleted or when a security rule is modified, as these are service-level events recorded in the activity log.

Why candidates choose this

Candidates may confuse activity log alerts with metric alerts, thinking any Azure alert can monitor performance metrics, or they may not understand that CPU utilization is a metric, not an activity log entry.

✗A resource lock and Azure AdvisorWrong answer — click to see why▾

Why this is wrong here

A resource lock prevents accidental deletion or modification of resources, and Azure Advisor provides best practice recommendations, but neither sends alerts based on performance metrics like CPU utilization.

★ When this WOULD be the correct answer

You need to prevent accidental deletion of a critical production VM and receive recommendations to improve its reliability and performance. In this scenario, you would configure a resource lock on the VM and use Azure Advisor to get actionable recommendations.

Why candidates choose this

Candidates may confuse Azure Advisor's monitoring capabilities with alerting, or think that resource locks are involved in notification workflows, leading them to select this option despite its irrelevance to metric-based alerting.

✗A budget alert and a private endpointWrong answer — click to see why▾

Why this is wrong here

A budget alert monitors cost thresholds, not CPU utilization, and a private endpoint secures network connectivity to Azure resources, not metrics. Neither component addresses the requirement to alert on CPU performance metrics.

★ When this WOULD be the correct answer

You need to receive an email when spending on a subscription exceeds $500, and you must ensure that a storage account is only accessible over a private network. In that case, a budget alert and a private endpoint would be correct.

Why candidates choose this

Candidates may confuse 'budget' with performance thresholds or think that a private endpoint is needed for monitoring, not realizing that CPU alerts require metric alerts and action groups.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-104 question is part of Courseiva's 1,053-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. The operations team wants an email and SMS notification whenever any production virtual machine's average CPU stays above 85 percent for 10 minutes. They also want to reuse the same notification targets for future alerts. What should they configure?

medium
  • A.A diagnostic setting on each VM that sends metrics to a storage account
  • ✓ B.An action group attached to a metric alert rule
  • C.A Log Analytics query alert with no notification target
  • D.A resource lock on the virtual machines

Why B: An action group in Azure Monitor defines the notification targets (email, SMS, etc.) for alerts, and a metric alert rule can be configured to trigger when the average CPU percentage exceeds 85% for 10 minutes. By attaching the same action group to multiple alert rules, the operations team can reuse the notification targets for future alerts without reconfiguring them each time.

Variation 2. A production virtual machine is experiencing intermittent performance spikes. The operations team wants an alert when average CPU usage stays above 80 percent for 10 minutes and wants email and SMS notifications sent automatically. What should the administrator configure in Azure Monitor?

medium
  • A.Create a log search alert on the VM performance data and attach a resource lock.
  • ✓ B.Create a metric alert on Percentage CPU and associate an action group with email and SMS receivers.
  • C.Assign an Azure Policy definition to the VM to stop it when CPU exceeds the threshold.
  • D.Enable diagnostic settings on the VM and send the data only to a storage account.

Why B: Azure Monitor metric alerts can evaluate real-time performance counters like Percentage CPU against a threshold (e.g., 80%) over a specified duration (e.g., 10 minutes). By associating an action group with email and SMS receivers, the alert automatically triggers the desired notifications without requiring log ingestion or complex queries.

Variation 3. A production virtual machine must trigger an immediate notification whenever average CPU stays above 85 percent for 15 minutes, and the same event must also start an Azure Function that opens an incident ticket. Which two Azure Monitor components should you configure? Select two.

medium
  • ✓ A.Create a metric alert rule on the VM CPU percentage.
  • ✓ B.Add an action group that sends email and invokes the Azure Function.
  • C.Enable a diagnostic setting on the VM without creating an alert rule.
  • D.Create a Log Analytics workspace and rely on manual queries only.
  • E.Apply a resource lock so CPU usage changes are blocked.

Why A: Both A and B are required. A metric alert rule monitors the Percentage CPU metric and fires when the average exceeds 85% for 15 minutes. The action group (B) is attached to that alert rule to send email notifications and invoke the Azure Function when the alert fires.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.