A cloud administrator is configuring monitoring for a critical financial application. The application processes transactions that must be completed within 500 milliseconds. If the average transaction time exceeds 400 milliseconds for more than 3 consecutive 1-minute intervals, a high-priority alert must be triggered. Which alerting configuration provides the MOST effective and timely notification for this scenario?
- AA multi-data point alarm that monitors average transaction time > 400ms for 3 out of 3 consecutive periods.
- BA composite alarm combining average transaction time and database CPU utilization metrics.
- CA metric math expression that calculates the average transaction time over a 3-minute period and triggers if > 400ms.
- DA simple threshold alert for average transaction time > 400ms.
Show answer & explanationAnswer & explanation
Correct answer: A. A multi-data point alarm that monitors average transaction time > 400ms for 3 out of 3 consecutive periods.
A multi-data point alarm (often called 'M out of N' or 'Datapoints to Alarm' in cloud monitoring services) is specifically designed for scenarios where a metric must exceed a threshold for a sustained period. This prevents false positives from transient spikes while ensuring timely notification for persistent degradation, precisely matching the requirement of 'more than 3 consecutive 1-minute intervals'.
Why the other options are wrong
- B. A composite alarm is useful for combining different alerts, but doesn't directly address the '3 consecutive 1-minute intervals' requirement for a single metric.
- C. A metric math expression calculating the average over 3 minutes would smooth out the data, but it wouldn't distinguish between a 3-minute average of 400ms (which might be 3x400ms) and a single spike within that period, nor would it guarantee 'consecutive' intervals in the same way a multi-datapoint alarm does.
- D. A simple threshold alert would trigger for any single minute exceeding 400ms, leading to false positives from transient spikes.
Multi-Data Point Alarm (M out of N)
An alarm configuration that triggers only when a metric exceeds a threshold for 'M' out of 'N' consecutive evaluation periods, preventing false positives from transient spikes.
- Requires sustained threshold breach to alert.
- Reduces alert fatigue from temporary fluctuations.
- Commonly used for critical performance metrics where consistency matters.
Memory trick: M-of-N: Multiple data points mean a real problem, not just a blip.