Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company has an Azure subscription that contains 100 virtual machines (VMs). You are designing a monitoring solution that must meet the following requirements: - Alert when any VM's CPU usage exceeds 90% for 15 minutes. - Alert when any VM's available memory drops below 1 GB. - Provide a centralized dashboard showing real-time performance metrics for all VMs. Which TWO Azure services should you include in the solution? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse Azure Monitor Workbooks with Azure Dashboards or Power BI, but Workbooks are the correct service for creating a centralized, real-time performance dashboard that integrates directly with Azure Monitor alerts and metrics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Monitor

Azure Monitor is the core service for collecting, analyzing, and acting on telemetry from Azure resources. It can collect CPU and memory metrics from VMs via the Azure Monitor Agent, and its alerting engine can trigger actions when CPU exceeds 90% for 15 minutes or available memory drops below 1 GB, meeting both alerting requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy is a governance and compliance service that evaluates resource configurations, such as allowed locations or mandatory tags, against defined policies. It operates at the control plane using Azure Resource Manager data, not at the virtual machine network/telemetry level. Because it cannot ingest CPU or memory time-series data or evaluate metric thresholds, it is incapable of providing real-time performance monitoring or alerting.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM and SOAR solution focused on security incident detection, threat hunting, and security alert response. While it can connect to various data sources, including some performance logs, its core design is for security analytics, not infrastructure performance monitoring. Sentinel does not provide built-in metric alerts for CPU or memory utilization and is the wrong tool when the requirement is purely operational telemetry with threshold-based actions.

  • ✓

    Azure Monitor

    Why this is correct

    Azure Monitor is the foundational monitoring service in Azure, collecting platform metrics and logs from resources, including virtual machines. When the Azure Diagnostics extension or Log Analytics agent is enabled, it captures guest OS metrics such as CPU percentage and memory utilization. Azure Monitor natively supports metric alerts that fire when a threshold is exceeded and can trigger action groups to send notifications or start automation. This makes it the primary correct service for the scenario's real-time performance monitoring and alerting need.

  • ✓

    Azure Monitor Workbooks

    Why this is correct

    Azure Monitor Workbooks are an interactive visualization and reporting feature built on top of Azure Monitor data. They let you combine metrics, logs, and queries into customizable, shareable dashboards that display CPU, memory, and other performance data. Because Workbooks are part of Azure Monitor, they do not replace the alerting capability but are correct for satisfying a dashboard requirement when visual presentation of the collected metrics is needed.

  • ✗

    Azure Automation

    Why it's wrong here

    Azure Automation is an orchestration and operations automation service that runs PowerShell or Python runbooks on a schedule or in response to webhooks. It does not collect performance telemetry, maintain metric time series, or provide built-in dashboards for VM health. While Azure Automation could be integrated into a monitoring response workflow (e.g., restart a VM after an alert), it is not a monitoring or dashboarding tool itself.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.