AZ-400 Implement an instrumentation strategy Practice Question
You are using Application Insights to monitor a web application. You need to create an alert that triggers when the average server response time exceeds 2 seconds over a 5-minute window. You want to minimize false positives by requiring the condition to be met for at least two consecutive 5-minute periods. What should you configure?
⚠ Common exam trap
The trap here is selecting a log search alert or using Maximum aggregation, which may seem simpler but fails to enforce the consecutive evaluation requirement or misinterprets the metric aggregation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A metric alert with a threshold of 2 seconds, aggregation type Average, period 5 minutes, and evaluation frequency 5 minutes, with an alert rule that triggers after two consecutive evaluations.
Metric alerts in Azure Monitor allow you to specify the aggregation (Average), period (5 minutes), evaluation frequency (5 minutes), and the number of consecutive evaluations before triggering. This precisely matches the requirement of alerting only when the average response time exceeds 2 seconds for two consecutive 5-minute windows, reducing false positives from transient spikes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A metric alert with a threshold of 2 seconds, aggregation type Maximum, period 5 minutes, and evaluation frequency 1 minute, with an alert rule that triggers immediately.
Why it's wrong here
Using Maximum aggregation would trigger on any single slow request, not the average, leading to false positives. Also, triggering immediately without consecutive evaluations does not meet the requirement of two consecutive periods. This configuration would be too sensitive and not aligned with the stated goal.
- ✗
An activity log alert that monitors the server response time metric and triggers when the average exceeds 2 seconds.
Why it's wrong here
Activity log alerts are for Azure resource operations (e.g., VM start, policy assignment), not for application performance metrics. They cannot monitor server response time. This option is incorrect because it uses the wrong alert type for the metric.
- ✗
A log search alert using a Kusto query that calculates the average response time over 5 minutes and triggers if the result exceeds 2 seconds.
Why it's wrong here
A log search alert can evaluate a query periodically, but it does not natively support requiring multiple consecutive evaluations to trigger. You could simulate this with a complex query, but it is not the straightforward configuration. Metric alerts are designed for this scenario with built-in consecutive evaluation settings.
- ✓
A metric alert with a threshold of 2 seconds, aggregation type Average, period 5 minutes, and evaluation frequency 5 minutes, with an alert rule that triggers after two consecutive evaluations.
Why this is correct
Metric alerts in Azure Monitor support specifying the aggregation, period, and evaluation frequency. To require two consecutive periods, you set the alert rule to trigger only after the condition is met for the specified number of evaluations. This reduces false positives by ensuring the threshold is breached consistently, not just in a single spike.
Go deeper
Related to this question
Learn chapter
Managing Infrastructure as Code Using Azure
Key term
Application Insights
Application Insights is an Azure monitoring service that helps developers detect, diagnose, and understand issues in live web applications by collecting telemetry data like requests, exceptions, and performance counters.
Key term
Metric
A metric is a quantifiable measurement used to assess the performance, health, or status of IT systems, networks, or applications.
About these practice questions
This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.