Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security engineer needs to configure Azure Monitor to detect when a specific security event ID (e.g., Event ID 4625 for failed logins) appears more than 50 times within a 15-minute window from any server connected to a Log Analytics workspace. Which type of alert rule should the engineer create?

  1. AMetric alert rule
  2. BAzure Service Health alert rule
  3. CLog search alert rule
  4. DActivity log alert rule
Show answer & explanation

Correct answer: C. Log search alert rule

Log search alert rules are used to run Kusto queries against data in a Log Analytics workspace and trigger an alert if the query results meet specific criteria, such as a count exceeding a threshold within a time window.

Why the other options are wrong

  • A. Metric alerts monitor numerical metrics, not specific event IDs within log data.
  • B. Azure Service Health alerts are for Azure service incidents, not custom log event monitoring.
  • D. Activity log alerts monitor control-plane events, not granular operating system or application logs.

Azure Monitor Log Search Alerts

Azure Monitor Log Search Alerts trigger when the results of a scheduled Kusto Query Language (KQL) query against Log Analytics data meet a specified condition, such as a count exceeding a threshold.

  • Queries log data in Log Analytics workspaces.
  • Uses KQL for flexible and powerful query conditions.
  • Ideal for detecting specific events, patterns, or trends in logs.

Memory trick: Logs are for searching, metrics are for measuring, activity is for actions, health is for service.

More Manage security operations questions