You have an Azure Log Analytics workspace collecting security-related performance counters from on-premises servers. You need alert rules that support dimensions, minimize creation time, and send a single notification both when the alert fires and when it is resolved. Which signal type should you use when creating the alert rules?
Choose an answer
Tap an option to check your answer.
Correct answer: Metric.
Why this is the answer
Metric alerts are the correct choice because they inherently support dimensions, allowing for more granular monitoring and filtering based on specific counter instances or server properties. They are also designed for quick evaluation, minimizing creation time. Crucially, metric alerts offer stateful monitoring, meaning they can track the alert's status and send a single notification for both activation and resolution, preventing alert storms. Activity logs track control-plane operations and events in Azure, not performance counters. Application logs are typically used for application-specific events and errors, not general security performance counters. Audit logs, while security-focused, primarily record security-related events and user activities, not performance metrics, and may not offer the same dimensional support or stateful notification capabilities as metric alerts for this specific scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed