A company is using Google Cloud Monitoring to observe the health and performance of its applications. They have configured several custom metrics to track application-specific security events, such as failed login attempts and suspicious API calls. They now need to create an automated alert that triggers a PagerDuty incident if the rate of failed login attempts exceeds 10 per minute for any user, but only for users accessing a specific critical application. How should this alert policy be configured in Cloud Monitoring?
- ACreate a metric-based alert using a MQL query that filters by the custom metric, application label, and aggregates failed attempts with a threshold.
- BCreate a log-based alert in Cloud Logging that scans for 'failed login' messages and sends notifications.
- CSet up a health check in Cloud Monitoring to monitor the application's availability, and link it to a PagerDuty notification channel.
- DConfigure Security Command Center's Event Threat Detection to monitor for failed logins to the critical application.
Show answer & explanationAnswer & explanation
Correct answer: A. Create a metric-based alert using a MQL query that filters by the custom metric, application label, and aggregates failed attempts with a threshold.
To detect a rate exceeding a threshold for a specific custom metric, filtered by a label (application) and then aggregated, a metric-based alert with a Monitoring Query Language (MQL) query is the most powerful and precise way. MQL allows for complex aggregations, filtering by labels, and thresholding based on rates over time. Log-based alerts are good for simple log patterns, but MQL provides more control over metric rates.
Why the other options are wrong
- B. Log-based alerts are simpler and might not easily support the 'rate exceeds X per minute *for any user*' requirement with the same precision as MQL on a custom metric.
- C. Health checks monitor application availability, not specific security events like failed login rates.
- D. Event Threat Detection identifies broader threats from logs, but the specific requirement for a custom metric rate alert on a specific application is best handled by Cloud Monitoring's MQL.
Cloud Monitoring MQL for Alerts
Monitoring Query Language (MQL) in Cloud Monitoring provides a powerful and flexible way to define alert conditions. It allows for complex data transformations, aggregations, filtering by labels, and thresholding on metrics, enabling precise alerting on specific patterns.
- Advanced querying for metrics.
- Supports complex aggregations and filtering.
- Ideal for precise, rate-based alerting.
Memory trick: MQL writes the rules for smart alerts.