Microsoft Certified: Azure Security Engineer AssociateManage security operationsEasy
A security engineer is configuring Azure Monitor to detect unusual network traffic patterns within a Virtual Network (VNet). They want to be alerted if the average inbound and outbound traffic for any VM within the VNet exceeds a specific threshold over a 5-minute period. Which type of alert rule should the engineer create?
- AMetric alert rule
- BActivity log alert rule
- CAzure Service Health alert rule
- DLog search alert rule
Show answer & explanationAnswer & explanation
Correct answer: A. Metric alert rule
Metric alert rules are specifically designed to monitor numerical values collected from resources, such as network traffic, CPU utilization, or disk I/O, against defined thresholds.
Why the other options are wrong
- B. Activity log alerts monitor events in the Azure Activity Log, not continuous metric data.
- C. Azure Service Health alerts notify about service incidents or planned maintenance, not resource metrics.
- D. Log search alerts analyze logs collected in Log Analytics, which is different from direct metric monitoring.
Azure Monitor Metric Alerts
Azure Monitor Metric Alerts trigger when a numerical metric value, such as CPU usage or network traffic, crosses a predefined threshold for a specified period.
- Monitors numerical data points collected over time.
- Ideal for performance and usage monitoring.
- Can aggregate data over different time granularities.
Memory trick: Metrics are for measuring, logs are for searching, activity is for actions, health is for service.