Microsoft Certified: Azure Administrator AssociateMonitor and maintain Azure resourcesMedium
A company is using Azure Monitor to collect logs and metrics from various Azure resources. They have configured an alert rule that triggers when CPU utilization on a specific VM exceeds 90% for 5 minutes. When the alert triggers, they need to automatically send an email to the operations team, post a message to a Microsoft Teams channel, and trigger an Azure Function to perform automated remediation. Which Azure Monitor component should be configured to achieve these automated actions?
- AMetric alert rule
- BDiagnostic settings
- CLog Analytics workspace
- DAction group
Show answer & explanationAnswer & explanation
Correct answer: D. Action group
An Action Group in Azure Monitor is a collection of notification preferences and actions that can be triggered by an Azure alert. It allows you to define multiple actions (email, Teams, Azure Function, etc.) to be executed when a specific alert condition is met, centralizing the response to alerts.
Why the other options are wrong
- A. A metric alert rule defines the condition that triggers an alert, but it needs an action group to specify what happens when the alert fires.
- B. Diagnostic settings configure where logs and metrics are sent (e.g., Log Analytics, storage account), not what actions to take on an alert.
- C. Log Analytics workspace is where logs are collected and queried, but it doesn't directly define automated actions for alerts.
Azure Monitor Action Group
A collection of notification preferences and automated actions that Azure Monitor alerts can trigger, allowing for a centralized response to incidents.
- Triggered by Azure alerts.
- Combines multiple actions (email, SMS, webhook, function).
- Centralizes alert response.
Memory trick: When an alert goes off, a 'group' of actions springs into motion.