Topic module

Azure Monitor, Logs, Alerts and Insights

Monitoring questions test metrics, log settings, Log Analytics, KQL queries, alert rules, action groups, alert processing rules, VM insights, storage insights, network insights, Network Watcher, and Connection Monitor.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-104

Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.

Core concepts

Concept 1

Azure Monitor, Logs, Alerts and Insights questions reward operational Azure administration judgment rather than simple service-name recall.

Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.

Concept 2

The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.

Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.

Concept 3

Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.

Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.

Risk pitfalls and guardrails

Using Azure Policy when the question asks who is allowed to perform an action.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Assuming backup exists before checking vault, policy, retention, and restore validation.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Memory anchors

Azure Monitor

Azure Monitor collects, analyzes, and acts on telemetry from Azure and other environments.

Metric

A metric is numeric time-series data used to track resource behavior.

Log Analytics

Log Analytics stores and queries log data collected by Azure Monitor.

KQL

Kusto Query Language queries logs and telemetry in Log Analytics.

Alert Rule

An alert rule defines a condition that triggers notifications or actions.

Action Group

An action group defines notifications or automation actions for alerts.

Alert Processing Rule

An alert processing rule suppresses or modifies alert handling under selected conditions.

VM Insights

VM insights monitors virtual machine performance and dependencies.

Connection Monitor

Connection Monitor tests and tracks network connectivity paths.

Diagnostic Setting

Diagnostic settings route platform logs and metrics to selected destinations.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

An administrator needs a near-real-time numerical series of a VM's Percentage CPU without querying log records. Which Azure Monitor data type should be used?

A team needs to analyze application events with message text, custom fields, and correlations across resources. Which data store and query approach fits?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.