AZ-305 Practice Question: Design identity, governance, and monitoring solutions
You are designing a monitoring solution for a critical application that runs on Azure Virtual Machines. The application generates custom performance counters. You need to alert when the custom counter exceeds a threshold and trigger an Azure Automation runbook to remediate. Which two Azure services should you combine? (Select TWO.)
⚠ Common exam trap
It's easy for candidates to confuse Log Analytics as a direct alerting and remediation service, when in fact it is a data repository that requires Azure Monitor to evaluate alerts and trigger actions via action groups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Monitor
Azure Monitor is the correct choice because it collects and analyzes custom performance counters from Azure VMs, enabling metric-based alert rules. When a threshold is exceeded, Azure Monitor can trigger an action group that invokes an Azure Automation runbook, providing automated remediation. This combination directly addresses the requirement to alert on custom counters and execute a runbook in response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Event Grid
Why it's wrong here
Azure Event Grid is a serverless event routing service that delivers discrete events (e.g., blob created, resource health changes) from publishers to subscribers. Although Azure Monitor alert rules can be configured to publish to Event Grid or call a webhook hosted by Event Grid, Event Grid itself performs no telemetry evaluation and cannot trigger actions based on a metric threshold crossing. It is therefore not the component that provides metric-based monitoring.
- ✓
Azure Monitor
Why this is correct
Azure Monitor is the core Azure platform service for collecting metrics, logs, and activity data and for alerting on that telemetry. A metric alert rule in Azure Monitor continuously evaluates resource metric values (e.g., CPU percentage, request count) against a threshold and fires an action group when the condition is met, making it the correct foundation for a monitoring and alerting solution.
- ✗
Log Analytics
Why it's wrong here
Log Analytics is an ingestion and query platform within Azure Monitor, optimized for storing log/event data and analyzing it with Kusto Query Language. While Log Analytics supports log alerts and can be a destination for diagnostic telemetry, it is not the service that creates metric alerts on automatic resource performance counters; metric alerts require Azure Monitor's metric store and alert rules.
- ✓
Azure Automation
Why this is correct
Azure Automation is a valid supporting service for a monitoring solution because its runbooks can be executed automatically when an alert fires. You can attach a runbook to an Azure Monitor alert through an action group or use a webhook to enable self-healing actions such as scaling out a resource, restarting an app, or rotating credentials. It does not do the monitoring itself but provides the responsive execution layer that makes the monitoring solution operational.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.