AZ-400 Implement an instrumentation strategy Practice Question
Your team uses GitHub Actions for CI/CD. You need to collect and analyze build and deployment logs centrally to identify recurring failures. Which service should you use to ingest and query these logs?
⚠ Common exam trap
The trap is picking Application Insights because it sounds like the 'monitoring' answer — but AZ-400 tests the distinction between APM telemetry (Application Insights) and centralized log ingestion/query (Log Analytics).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Log Analytics
Azure Log Analytics is the service designed to ingest, store, and query large volumes of log data using Kusto Query Language (KQL), making it ideal for centralizing GitHub Actions build and deployment logs and identifying recurring failures. You can create a Log Analytics workspace, send logs via the Logs Ingestion API or diagnostic settings, and run KQL queries to spot patterns. This directly satisfies the requirement to collect and analyze logs centrally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Monitor Alerts
Why it's wrong here
Azure Monitor Alerts is a notification and response feature that evaluates conditions on collected metrics or log queries; it does not ingest or store CI/CD pipeline logs centrally, so it cannot serve as the destination for GitHub Actions workflow run logs.
- ✓
Azure Log Analytics
Why this is correct
Azure Log Analytics is the log ingestion, storage, and query service within Azure Monitor; it can collect GitHub Actions workflow run logs via diagnostic settings or integrations, enabling you to centralize CI/CD logs and analyze them with KQL queries.
- ✗
GitHub Insights
Why it's wrong here
GitHub Insights is a metrics dashboard that provides analytics on repository activity, workflow runs, and developer productivity; it does not accept or store external log streams, so it cannot collect and centrally manage CI/CD pipeline logs.
- ✗
Application Insights
Why it's wrong here
Application Insights is an application performance monitoring (APM) service designed to ingest telemetry like requests, dependencies, and custom events from applications; it is not intended for collecting infrastructure or CI/CD pipeline execution logs from GitHub Actions.
Go deeper
Related to this question
Learn chapter
Implementing Deployment Patterns and Strategies
Key term
KQL
Kusto Query Language is a powerful read-only query language used to explore, analyze, and visualize large datasets, most notably in Azure Data Explorer and Microsoft Sentinel.
Key term
Log Analytics
Log Analytics is a cloud-based service that collects, analyzes, and visualizes machine-generated log data from various sources to help IT teams monitor systems and troubleshoot issues.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.