Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

Which TWO Azure services can be used to monitor Azure Data Factory pipeline runs and set up alerts?

⚠ Common exam trap

DP-203 often tests the distinction between monitoring/alerting services (Azure Monitor, Log Analytics) and governance/security services (Azure Policy, Microsoft Sentinel, Azure Advisor), so candidates may incorrectly select Azure Policy for alerting or Microsoft Sentinel for pipeline monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log Analytics

Azure Monitor (option D) is the native platform for collecting metrics and activity/diagnostic logs from Azure Data Factory and for creating alert rules (metric alerts, log search alerts, activity log alerts) that trigger on pipeline run failures or durations, so it directly satisfies the monitoring-and-alerting requirement. Log Analytics (option A) is the service where ADF diagnostic logs are stored and queried with KQL, and it powers log search alerts (via Azure Monitor) on pipeline run records such as PipelineRun and ActivityRun, making it a valid way to monitor runs and set alerts. Microsoft Sentinel (B) is a SIEM/SOAR for security analytics, not pipeline operational monitoring; Azure Policy (C) enforces governance/compliance rules rather than monitoring runs; and Azure Advisor (E) only provides best-practice recommendations, not run monitoring or alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Log Analytics

    Why this is correct

    Log Analytics stores Azure Data Factory diagnostic logs, and alert rules defined against that workspace trigger notifications on pipeline run failures or duration thresholds. This satisfies the monitoring and alerting requirement for Data Factory pipeline runs.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel analyses security events from connected sources; it does not natively surface Data Factory pipeline run status or raise activity alerts. Azure Monitor and Data Factory alerts handle run monitoring, so Sentinel is the wrong service here.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy evaluates resource compliance against governance rules, not pipeline run telemetry, so it cannot raise alerts on Data Factory activity outcomes. It is tempting because it does enforce configuration standards across subscriptions, and it would be the right choice when you need to audit or deny non-compliant resource deployments.

  • ✓

    Azure Monitor

    Why this is correct

    Azure Monitor ingests Data Factory pipeline run metrics and activity logs, then drives alert rules and action groups. This satisfies the requirement to both monitor pipeline runs and configure alerts, since Data Factory natively emits diagnostic telemetry into Azure Monitor.

  • ✗

    Azure Advisor

    Why it's wrong here

    Azure Advisor only surfaces recommendations on cost, security, reliability and performance; it holds no pipeline run telemetry and cannot raise alerts on activity outcomes. It is tempting because it does monitor Azure resources, but it would be the right choice for reviewing configuration best practise, not for tracking Data Factory run status.

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DP-203

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO Azure services can you use to monitor data processing pipelines in Azure Data Factory?

easy
  • ✓ A.Log Analytics workspace
  • B.Azure Sentinel
  • C.Azure Dashboard
  • D.Azure Service Health
  • ✓ E.Azure Monitor

Why A: Azure Monitor (E) is correct because it is the native platform that collects metric and diagnostic-log telemetry from Azure Data Factory, including pipeline run, activity run, and trigger run records, which you query via Log Analytics or visualize in metrics/alert rules. A Log Analytics workspace (A) is correct because ADF diagnostic settings stream those pipeline/activity/trigger logs and metrics into the workspace, where Kusto Query Language (KQL) queries over tables such as ADFPipelineRun and ADFActivityRun enable detailed pipeline monitoring and alerting. Azure Sentinel (B) is a SIEM/SOAR security product for threat detection, not a data-pipeline monitoring tool, so it does not belong. Azure Dashboard (C) is only a visualization surface for pinned tiles and does not itself collect or monitor ADF telemetry. Azure Service Health (D) reports platform-wide Azure outages and planned maintenance, not the execution status of your ADF pipelines.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.