DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Which TWO Azure services can be used to monitor Azure Data Factory pipeline runs and set up alerts?
⚠ Common exam trap
DP-203 often tests the distinction between monitoring/alerting services (Azure Monitor, Log Analytics) and governance/security services (Azure Policy, Microsoft Sentinel, Azure Advisor), so candidates may incorrectly select Azure Policy for alerting or Microsoft Sentinel for pipeline monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log Analytics
Azure Monitor (option D) is the native platform for collecting metrics and activity/diagnostic logs from Azure Data Factory and for creating alert rules (metric alerts, log search alerts, activity log alerts) that trigger on pipeline run failures or durations, so it directly satisfies the monitoring-and-alerting requirement. Log Analytics (option A) is the service where ADF diagnostic logs are stored and queried with KQL, and it powers log search alerts (via Azure Monitor) on pipeline run records such as PipelineRun and ActivityRun, making it a valid way to monitor runs and set alerts. Microsoft Sentinel (B) is a SIEM/SOAR for security analytics, not pipeline operational monitoring; Azure Policy (C) enforces governance/compliance rules rather than monitoring runs; and Azure Advisor (E) only provides best-practice recommendations, not run monitoring or alerting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Log Analytics
Why this is correct
Log Analytics stores Azure Data Factory diagnostic logs, and alert rules defined against that workspace trigger notifications on pipeline run failures or duration thresholds. This satisfies the monitoring and alerting requirement for Data Factory pipeline runs.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel analyses security events from connected sources; it does not natively surface Data Factory pipeline run status or raise activity alerts. Azure Monitor and Data Factory alerts handle run monitoring, so Sentinel is the wrong service here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy evaluates resource compliance against governance rules, not pipeline run telemetry, so it cannot raise alerts on Data Factory activity outcomes. It is tempting because it does enforce configuration standards across subscriptions, and it would be the right choice when you need to audit or deny non-compliant resource deployments.
- ✓
Azure Monitor
Why this is correct
Azure Monitor ingests Data Factory pipeline run metrics and activity logs, then drives alert rules and action groups. This satisfies the requirement to both monitor pipeline runs and configure alerts, since Data Factory natively emits diagnostic telemetry into Azure Monitor.
- ✗
Azure Advisor
Why it's wrong here
Azure Advisor only surfaces recommendations on cost, security, reliability and performance; it holds no pipeline run telemetry and cannot raise alerts on activity outcomes. It is tempting because it does monitor Azure resources, but it would be the right choice for reviewing configuration best practise, not for tracking Data Factory run status.
Go deeper
Related to this question
Learn chapter
Monitor Data Storage and Processing
Key term
Azure Data Factory
Azure Data Factory is a cloud-based data integration service that lets you create, schedule, and orchestrate data pipelines to move and transform data from various sources to destinations.
Key term
Data Transformation Pipelines
Data transformation pipelines are automated sequences of steps that take raw data from a source, clean and reshape it into a usable format, and then load it into a destination for analysis or storage.
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DP-203
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO Azure services can you use to monitor data processing pipelines in Azure Data Factory?
easy- ✓ A.Log Analytics workspace
- B.Azure Sentinel
- C.Azure Dashboard
- D.Azure Service Health
- ✓ E.Azure Monitor
Why A: Azure Monitor (E) is correct because it is the native platform that collects metric and diagnostic-log telemetry from Azure Data Factory, including pipeline run, activity run, and trigger run records, which you query via Log Analytics or visualize in metrics/alert rules. A Log Analytics workspace (A) is correct because ADF diagnostic settings stream those pipeline/activity/trigger logs and metrics into the workspace, where Kusto Query Language (KQL) queries over tables such as ADFPipelineRun and ADFActivityRun enable detailed pipeline monitoring and alerting. Azure Sentinel (B) is a SIEM/SOAR security product for threat detection, not a data-pipeline monitoring tool, so it does not belong. Azure Dashboard (C) is only a visualization surface for pinned tiles and does not itself collect or monitor ADF telemetry. Azure Service Health (D) reports platform-wide Azure outages and planned maintenance, not the execution status of your ADF pipelines.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.