AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization is deploying a critical application in Azure that must maintain an uptime SLA of 99.99%. The application runs on Azure Virtual Machines in a single region. You need to design a monitoring solution that alerts the operations team within 5 minutes of any VM unavailability. The solution must minimize false positives and avoid alert fatigue. What should you include in the design?
⚠ Common exam trap
Many exam-takers confuse guest OS-level monitoring (heartbeats or guest OS events) with hypervisor-level availability monitoring, leading them to choose options that depend on the guest OS being responsive, which fails when the VM is truly unavailable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Azure Monitor VM insights with availability metric alerts set to fire when the VM is unavailable for 2 out of the last 5 minutes.
VM insights availability metric alerts use the 'VM Availability' metric (a composite metric from the Azure Monitor agent) that tracks the VM's running state. Configuring it to fire when the VM is unavailable for 2 out of the last 5 minutes provides a 2-minute evaluation window, which balances the 5-minute notification requirement with a tolerance for transient blips, minimizing false positives. This approach directly monitors the VM's availability at the hypervisor level without relying on guest OS signals, ensuring reliable uptime detection for the 99.99% SLA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure Azure Monitor VM insights with availability metric alerts set to fire when the VM is unavailable for 2 out of the last 5 minutes.
Why this is correct
VM insights availability metric uses a combination of VM heartbeat and compute state to produce a rolling availability percentage. Alerting on 2 unavailable minutes out of the last 5 reliably signals sustained unavailability while ignoring transient network or agent blips. This dynamic-threshold approach directly measures the VM's availability and is the most precise option for a critical application requiring immediate detection of downtime.
- ✗
Create an Azure Service Health alert for the 'Virtual machine' service.
Why it's wrong here
Azure Service Health alerts are scoped to platform-level incidents, planned maintenance, and regional service outages, not to the operational state of an individual VM. A Service Health alert for 'Virtual machine' would notify you only if the Azure compute service itself is degraded, which does not detect a specific VM that is unavailable. Therefore it cannot meet the requirement to alert when your particular application VM goes down.
- ✗
Create an Azure Monitor alert based on the Activity Log for 'Virtual Machine Guest OS Unresponsive' events.
Why it's wrong here
The Activity Log is a control-plane log that records management operations such as create, start, stop, and resize for Azure resources; it does not contain guest OS responsiveness data. Resource Health events like 'Guest OS Unresponsive' are not stored in the Activity Log for alerting in this way, and an Activity Log alert cannot monitor the in-VM health of your application. This makes the approach fundamentally unable to detect the actual VM unavailability scenario.
- ✗
Deploy the Log Analytics agent on each VM and create an alert for when heartbeat data is missing for 5 minutes.
Why it's wrong here
Heartbeat absence from the Log Analytics agent for 5 minutes can be triggered by agent delays, network path interruptions, or agent updates even when the VM and guest OS are functioning normally. This single-signal metric creates false positives and contributes to alert fatigue because it lacks the corroborating VM-state information that a combined availability metric provides. It also requires additional agent deployment and management, and it is not as accurate as the dedicated availability alerting in VM insights.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.