AZ-305 Practice Question: Design identity, governance, and monitoring solutions
You need to monitor Azure resources and send alerts when the CPU usage of a virtual machine exceeds 90% for 5 minutes. Which two Azure services should you use? (Select TWO.)
⚠ Common exam trap
Test-takers frequently confuse Log Analytics (a log query tool) with Azure Monitor (the alerting engine), or mistakenly think Application Insights can monitor VM-level metrics, when it is designed for application-level telemetry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Monitor Action Groups
Azure Monitor is the core service for collecting and analyzing metrics and logs from Azure resources. It can be configured with metric alerts that trigger when CPU usage exceeds 90% for 5 minutes. Action Groups define the notification and response actions (e.g., email, SMS, webhook) that are executed when the alert fires, making them essential for sending alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Monitor Action Groups
Why this is correct
An Azure Monitor Action Group is the notification endpoint that alert rules invoke when a condition fires—it defines delivery channels such as email, SMS, voice, webhook, ITSM, or an automation runbook. Without an action group, an alert rule may log the hitting state but cannot actually send an email or SMS to operations staff. Therefore, for the specific goal of 'sending alerts,' the action group is the direct, correct component that carries out the notification.
- ✗
Log Analytics
Why it's wrong here
A Log Analytics workspace is a centralized repository that stores log data and enables KQL queries, dashboards, and long-term trend analysis; it does not itself evaluate numeric performance metrics or send notifications when a threshold is breached. Although Azure Monitor can generate log-based alert rules from Log Analytics queries, the workspace is only the data source and analysis engine, not the alert delivery mechanism. Thus, Log Analytics is the wrong choice when the requirement is to send metric threshold alerts on Azure resource metrics.
- ✓
Azure Monitor
Why this is correct
Azure Monitor is the overarching Azure service that collects performance metrics and activity logs from resources like virtual machines, then runs metric alert rules to evaluate those signals against thresholds. It is the correct monitoring platform because it does the underlying data collection and condition evaluation, but it needs an action group to carry out the notification step when an alert triggers. For this reason, Azure Monitor is a correct part of the solution, but it is the detection layer rather than the delivery layer.
- ✗
Application Insights
Why it's wrong here
Application Insights is a feature of Azure Monitor designed for application performance monitoring—it tracks request rates, dependency failures, page views, and custom telemetry emitted from instrumented application code. It does not natively monitor the CPU, memory, or disk counters of the underlying Azure VM infrastructure, so its alerts focus on application-level signals rather than resource metric thresholds. Choosing Application Insights would point monitoring at the wrong telemetry source for a VM-level metric alert.
- ✗
Event Grid
Why it's wrong here
Event Grid is a highly scalable, serverless event-routing service that delivers discrete occurrence notifications—like a resource state change, a blob upload, or an IoT message—to subscriber endpoints such as Azure Functions, webhooks, or Service Bus. It is not built to continuously sample numerical metrics, evaluate threshold expressions, or keep an alert in a fired state over a period of time. Even though you could feed an already-generate alert into Event Grid, it cannot itself perform the metric evaluation needed to send the original alert, so it is incorrect for this requirement.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.