Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy

A security engineer is configuring Azure Monitor to detect unusual network traffic patterns within a Virtual Network (VNet). They want to be alerted if the average inbound and outbound traffic for any VM within the VNet exceeds a specific threshold over a 5-minute period. Which type of alert rule should the engineer create?

  1. AMetric alert rule
  2. BActivity log alert rule
  3. CAzure Service Health alert rule
  4. DLog search alert rule
Show answer & explanation

Correct answer: A. Metric alert rule

Metric alert rules are specifically designed to monitor numerical values collected from resources, such as network traffic, CPU utilization, or disk I/O, against defined thresholds.

Why the other options are wrong

  • B. Activity log alerts monitor events in the Azure Activity Log, not continuous metric data.
  • C. Azure Service Health alerts notify about service incidents or planned maintenance, not resource metrics.
  • D. Log search alerts analyze logs collected in Log Analytics, which is different from direct metric monitoring.

Azure Monitor Metric Alerts

Azure Monitor Metric Alerts trigger when a numerical metric value, such as CPU usage or network traffic, crosses a predefined threshold for a specified period.

  • Monitors numerical data points collected over time.
  • Ideal for performance and usage monitoring.
  • Can aggregate data over different time granularities.

Memory trick: Metrics are for measuring, logs are for searching, activity is for actions, health is for service.

More Manage security operations questions