AZ-400 Implement an instrumentation strategy Practice Question
Exhibit
Refer to the exhibit.
```json
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspaceName": {
"type": "string"
},
"location": {
"type": "string"
}
},
"resources": [
{
"type": "Microsoft.OperationalInsights/workspaces",
"apiVersion": "2022-10-01",
"name": "[parameters('workspaceName')]",
"location": "[parameters('location')]",
"properties": {}
},
{
"type": "Microsoft.OperationalInsights/workspaces/savedSearches",
"apiVersion": "2020-08-01",
"name": "[concat(parameters('workspaceName'), '/PipelineFailures')]",
"dependsOn": [
"[resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspaceName'))]"
],
"properties": {
"category": "Azure Pipelines",
"displayName": "Pipeline Failures in Last 24 Hours",
"query": "AzureDevOpsPipelineEvents_CL | where TimeGenerated > ago(24h) and Result_s == 'Failed'"
}
}
]
}
```Refer to the exhibit. You deploy this ARM template to create a Log Analytics workspace and a saved search. After deployment, you notice that the saved search returns no results even though there are failed pipeline runs. What is the most likely reason?
⚠ Common exam trap
AZ-400 often tests the distinction between control-plane deployment success and data-plane readiness — candidates assume a successful ARM deployment means the query will work, forgetting that custom tables must exist before KQL can return results.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The custom table 'AzureDevOpsPipelineEvents_CL' does not exist in the workspace.
The saved search queries the custom table 'AzureDevOpsPipelineEvents_CL', which is created by the Azure DevOps connector or a custom data ingestion pipeline. If that table has never been created in the target Log Analytics workspace, the saved search KQL query will return zero rows even when failed pipeline runs exist elsewhere. The ARM template only defines the workspace and the saved search — it does not create the underlying custom table or wire up the data source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The savedSearch API version is not supported.
Why it's wrong here
The savedSearch resource type is supported in ARM, so the API version is not the cause; the query itself or its category and scope determine whether results appear. It is tempting because unsupported API versions do fail deployments, and would be correct if the template had been rejected outright.
- ✗
The Log Analytics workspace API version is incorrect.
Why it's wrong here
An incorrect API version typically causes deployment failure or schema rejection, not a silently empty saved search. The likely cause is a query scoping issue, such as the wrong table or time range. API versioning matters when resource schemas change between releases.
- ✓
The custom table 'AzureDevOpsPipelineEvents_CL' does not exist in the workspace.
Why this is correct
The ARM template deployment fails because the saved search references the custom log table 'AzureDevOpsPipelineEvents_CL', but that table does not exist in the workspace. Custom tables with the _CL suffix must be created beforehand (or data must be ingested to auto-create them); ARM templates do not implicitly create custom tables just because a saved search queries them.
- ✗
The category 'Azure Pipelines' is misspelled.
Why it's wrong here
The category property in a saved search is a free-form, user-defined label used for organization in the Azure portal; it is not checked against a fixed list or used in resource validation, so a misspelling of 'Azure Pipelines' would not cause a deployment error.
Go deeper
Related to this question
Learn chapter
Source Control Strategy Design
Key term
ARM template
An ARM template is a JSON file that defines the infrastructure and configuration for Azure resources, enabling repeatable and consistent deployments.
Key term
Pipeline
A pipeline is an automated series of steps that takes code from development to production, ensuring quality and speed.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.