Refer to the exhibit. You deploy this ARM template to create an Azure Monitor Workbook. The template deploys successfully. What will the workbook display?
This is correct because the query references the Processor object with counter '% Processor Time' and then uses summarize avg(CounterValue) by bin(TimeGenerated, 5m). The average of that counter over each 5-minute window is exactly CPU utilization averaged over 5-minute intervals, and the render timechart visualizes those averages over time. No other object or counter is selected.
Why this answer
The ARM template configures an Azure Monitor Workbook to query the `InsightsMetrics` table for the `cpu_usage_percentage` metric, which is collected by Azure Monitor Agent (AMA) at a default granularity of 1 minute. The workbook uses the `avg` aggregation and a time grain of `5m` (5 minutes) in the query, so it displays CPU utilization averaged over 5-minute intervals. The `summarize` operator with `bin(TimeGenerated, 5m)` explicitly groups data into 5-minute buckets, making option B correct.
Exam trap
The trap here is that candidates assume the default collection interval (1 minute) determines the display granularity, but the `bin()` function in the KQL query explicitly overrides that to 5-minute averages, making option B correct instead of a 1-hour or raw interval.
How to eliminate wrong answers
Option A is wrong because the query uses `bin(TimeGenerated, 5m)` to aggregate data into 5-minute intervals, not 1-hour intervals; a 1-hour interval would require `bin(TimeGenerated, 1h)`. Option C is wrong because the query filters for `cpu_usage_percentage` (CPU metric), not memory utilization; memory would require a metric like `memory_available_bytes` or `memory_percentage`. Option D is wrong because the query targets CPU utilization, not disk I/O; disk I/O would involve metrics such as `disk_read_bytes_per_second` or `disk_write_operations_per_second`.