exam questions

Exam AZ-103 All Questions

View all questions & answers for the AZ-103 exam

Exam AZ-103 topic 3 question 10 discussion

Actual exam question from Microsoft's AZ-103
Question #: 10
Topic #: 3
[All AZ-103 Questions]

You have an Azure virtual machine named VM1.
Azure collects events from VM1.
You are creating an alert rule in Azure Monitor to notify an administrator when an error is logged in the System event log of VM1.
You need to specify which resource type to monitor.
What should you specify?

  • A. metric alert
  • B. Azure Log Analytics workspace
  • C. virtual machine
  • D. virtual machine extension
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Azure Monitor can collect data directly from your Azure virtual machines into a Log Analytics workspace for detailed analysis and correlation. Installing the Log
Analytics VM extension for Windows and Linux allows Azure Monitor to collect data from your Azure VMs.
Incorrect Answers:
B: Azure Log Analytics workspace is used for on-premises computers monitored by System Center Operations Manager.
Reference:
https://docs.microsoft.com/en-us/azure/azure-monitor/learn/quick-collect-azurevm

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
redondo310
Highly Voted 5 years, 4 months ago
Thier answer is wrong. The answer is "C". Go to Azure Monitor > Alerts > New Alert > Select Resource > .... Here you can select a resource type, since the question refers to VM1, you need to select the virtual machine type. Selecting a type is not required but their answer is looking for virtual machine type.
upvoted 48 times
sammyboy
5 years ago
Bur the question is referring to "System Events" only
upvoted 2 times
...
trade4living
4 years, 9 months ago
well aid.. I dunno why few are simply fooling . Its "C" https://www.udemy.com/course/microsoft-certified-azure-administrator/learn/lecture/13160056#overview Search for monitor --> metrics --> select resource type --> VM
upvoted 2 times
...
...
Lubomir
Highly Voted 5 years, 2 months ago
I think the correct answer is B - Azure Log Analytics workspace. You can collect Windows Event logs into Log Analytics workspace https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources-windows-events Then you can create alert rule, with resource type "Azure Log Analytics workspace" and specify the condition based on query from collected logs. https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-log
upvoted 35 times
asdfgh1234567
5 years, 1 month ago
^^^^ THIS ^^^^ Event Logs are written to the Log Analytics Workspace. The Alert rule needs to be triggered based on a Query run against the Log Analytics Workspace. Therefore the alert resource is the Log Analytics Workspace.
upvoted 11 times
zyta
4 years, 9 months ago
I agree - nice described here: https://docs.microsoft.com/en-us/azure/azure-monitor/insights/monitor-vm-azure#configure-log-analytics-workspace
upvoted 4 times
...
...
...
tashakori
Most Recent 1 year, 2 months ago
B is the right answer
upvoted 1 times
...
Ahkhan
1 year, 6 months ago
Azure Log Analytics Workspace is the answer in 2023.
upvoted 1 times
...
Durden871
2 years, 2 months ago
Wow there's a lot of different answers. From Udemy: Explanation Correct Answer(s): Azure Log Analytics workspace – Logs contain different kinds of data organized into records with different sets of properties for each type. You can create and test queries using Log Analytics in the Azure portal and then either directly analyze the data using these tools or save queries for use with visualizations or alert rules. You need to select your Log Analytics workspace as the resource, since this is a log based alert signal. https://docs.microsoft.com/en-us/windows-server/storage/storage-spaces/configure-azure-monitor Wrong Answers: Virtual machine extension – This is to configure post-deployment configurations on a virtual machine. Virtual machine –Logs will be sent to Log destination like Log analytics workspace, nothing gets persisted inside a virtual machine. Metric alert – Metric is for alerts based on numbers like CPU usage, Memory usage etc.
upvoted 1 times
...
yeanlingmedal71
3 years, 1 month ago
For the first step to create the new alert tule, under the Create Alert section, you are going to select your Log Analytics workspace as the resource, since this is a log based alert signal. The log data goes to the analytics workspace and it is from there that the alert is triggered.
upvoted 2 times
...
clouddba
3 years, 11 months ago
Answer: B: Azure Log Analytics workspace is used for on-premises computers monitored by System Center Operations Manager. Highlighted answer is wrong but description is pretty clear :)
upvoted 2 times
...
datts
3 years, 11 months ago
Just tested. Correct answer is B. Azure Log Analytics workspace. Reason although you can set alert on VM and VM extensions, only on Log Analytics can you get System event logs, to set alert on.
upvoted 4 times
...
Tonyluo
4 years, 2 months ago
From this doc, it seems the log analytics workspace is also considered a resource: https://docs.microsoft.com/en-us/azure/azure-monitor/vm/quick-collect-azurevm And the VM extension is also needed.
upvoted 2 times
...
Thanveer
4 years, 4 months ago
The Clue is "resource type to monitor." VM is the answer.
upvoted 2 times
...
OsimIndia
4 years, 4 months ago
Here is the correct answer. refer pic at Point 4 ...from below source link Source: https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-log#creating-log-alert-for-log-analytics-and-application-insights-from-the-alerts-management. our test condition to monitor error is in LA workspace,,, azure monitor monitors this LA workspace ...
upvoted 1 times
OsimIndia
4 years, 4 months ago
Typo. Here is the correct answer. refer pic at Point 4 of """"Creating log alert for Log Analytics and Application Insights from the alerts management"""" ...from below source link Source: https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-log#creating-log-alert-for-log-analytics-and-application-insights-from-the-alerts-management. our test condition to monitor error is in LA workspace,,, azure monitor monitors this LA workspace ...
upvoted 1 times
...
...
aabdous
4 years, 6 months ago
Good Answer is B. Azure Log Analytics workspace. You can't monitor events with virtual machines. A & D aren't resources.
upvoted 2 times
...
takethisplease247
4 years, 6 months ago
signal type: Log alerts, resource type: Log Analytics workspace
upvoted 2 times
...
Thi
4 years, 6 months ago
C. virtual machine
upvoted 1 times
...
Thi
4 years, 6 months ago
C. virtual machine
upvoted 1 times
...
nyento
4 years, 7 months ago
correct answer is C. I have tried it and the only option in the list one can choose as a resource is virtual machine.
upvoted 1 times
...
AustinY
4 years, 9 months ago
To test this out, I have created a VM and enabled logging on it. When you enable logging, Azure will create a default Log Analytics Workspace. Next, I went in monitor to create an alert for System Errors. In Monitor, we can either choose VM or Log Analytics as the source of the alert. If you select, VM as the source of the alert, there is no error log option but Activity Logs. If you select Log Analytics space, System Error option will be available to create an alert. May be the detail could be "/...Azure collects events from VM1". You collect the events somewhere, which is a Log Analytics Workspace. This is, in turn, the source of the alert. Quite confusing guys... I would go with B.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...