Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security engineer needs to configure Azure Monitor to alert when the CPU utilization of any virtual machine within a specific resource group exceeds 90% for more than 5 minutes. The alert should be sent to a specific email distribution list. Which alert type and configuration combination should the engineer use?

  1. AActivity log alert for 'CPU utilization exceeded' event, targeting the resource group.
  2. BLog search alert querying Azure Activity Log for high CPU events, with a 5-minute frequency.
  3. CMetric alert for 'Percentage CPU' metric, with a static threshold of 90% and email action group.
  4. DSmart detection alert configured for VM performance anomalies, with email notification.
Show answer & explanation

Correct answer: C. Metric alert for 'Percentage CPU' metric, with a static threshold of 90% and email action group.

Metric alert rules are designed to monitor numerical metrics, such as CPU utilization. Configuring a metric alert for the 'Percentage CPU' metric with a static threshold of 90% and a 5-minute aggregation period directly addresses the requirement for detecting high CPU usage and sending notifications.

Why the other options are wrong

  • A. Activity log alerts monitor control plane operations, not continuous performance metrics like CPU utilization.
  • B. While a log search alert *could* be configured if CPU data is sent to Log Analytics, the most direct and efficient method for monitoring a standard metric like CPU utilization is a metric alert.
  • D. Smart detection alerts are for predefined anomaly detection, not for specific, static threshold monitoring of a known metric like CPU utilization.

Azure Monitor Metric Alerts

Alert rules in Azure Monitor that trigger when a numerical metric (e.g., CPU, memory, network I/O) crosses a predefined threshold.

  • Monitors resource performance and usage.
  • Can use static thresholds or dynamic thresholds (machine learning).
  • Supports various action groups for notifications and automation.

Memory trick: Alerts are like 'tripwires' for different 'events' or 'numbers'.

More Manage security operations questions