SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
AZ-104 · Domain 5

Monitor and maintain Azure resources practice questions

Monitor and maintain Azure resources is worth 14% of the AZ-104 exam — the lightest of the 5 domains. Azure Monitor metrics, logs, and alerting, plus backup and disaster recovery. Official weighting 10–15%. 6 fully worked examples are further down this page, answers included.

Exam weight
14%
the lightest of the 5 domains
Questions
40
across 2 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Monitor and maintain Azure resources questions, fully explained

Questions from the AZ-104 bank mapped to domain 5, with the answer key and the reasoning behind every option. None of them repeat the examples on the main AZ-104 practice page.

Question 1Monitor and maintain Azure resources

In Azure Monitor metrics explorer, an administrator charts the Transactions metric for a storage account and wants to see a separate line for each API operation type (for example GetBlob versus PutBlob) on the same chart. What should the administrator apply to the chart?

Choose one.

  • a
    A second metric namespace

    A namespace groups related metrics for a resource type (for example blob versus file metrics). Changing namespace changes which metrics are listed; it does not break one metric into per-operation series.

  • b
    Splitting by the API name dimension Correct

    Applying splitting on a metric dimension renders one series per dimension value, so each API operation type gets its own line on the same chart.

  • c
    The Count aggregation

    Changing the aggregation alters how samples in each time interval are combined into a single value. It still produces one line, not one line per operation type.

  • d
    A dynamic threshold

    Dynamic thresholds belong to metric alert rules, where machine learning derives the alert boundary from historical data. They have no effect on how a metrics explorer chart is drawn.

The concept

Many platform metrics carry dimensions - name-value properties such as API name or response type. Metrics explorer can filter on a dimension (limit which values are included) or split on a dimension (draw a separate series per value).

Why that’s the answer

Splitting by the API name dimension is exactly the feature that turns a single aggregated Transactions line into one line per operation type. A namespace only selects which set of metrics is available, an aggregation only changes how each time bucket is summarized into one number, and dynamic thresholds are an alerting concept that never appears on an explorer chart.

How to reason it out
  1. In metrics explorer, select the storage account, the Transactions metric, and an aggregation such as Sum.
  2. Select Apply splitting and choose the API name dimension.
  3. Optionally add a filter on the same dimension to limit the chart to specific operations of interest.

Exam tip: Use dimension splitting in metrics explorer to render one series per dimension value; use filtering to narrow which values are charted.

Azure Monitor: Metrics, Logs, Diagnostic Settings & Alerts (AZ-104) — the lesson that teaches this.

Question 2Monitor and maintain Azure resources

An administrator is charting the Percentage CPU metric for a virtual machine and needs the chart to show the single worst spike within each time interval so that short bursts are not hidden. Which aggregation should the administrator select?

Choose one.

  • a
    Avg

    Avg divides the sum of samples by their count within each interval. A brief spike averaged with many normal samples is flattened, which is exactly what the administrator wants to avoid.

  • b
    Sum

    Sum adds all samples in the interval. For a percentage metric this produces meaningless values (for example several hundred percent) rather than revealing the peak.

  • c
    Count

    Count reports how many samples were collected in the interval, which measures data arrival rate, not CPU utilization at all.

  • d
    Max Correct

    The Max aggregation plots the highest sample recorded in each time granularity interval, so short CPU spikes remain visible instead of being smoothed away.

The concept

Metrics explorer aggregates raw metric samples into one value per time granularity interval using Avg, Min, Max, Sum, or Count. The chosen aggregation determines what the chart reveals or hides.

Why that’s the answer

Max surfaces the peak sample in every interval, making it the right choice for spotting short-lived spikes. Avg smooths bursts into the background, Sum is nonsensical for a percentage utilization metric, and Count reflects the number of collected samples rather than their values.

How to reason it out
  1. Open metrics explorer for the VM and select the Percentage CPU metric.
  2. Change the aggregation dropdown from Avg to Max.
  3. Reduce the time granularity if needed so intervals are short enough to isolate individual spikes.

Exam tip: Pick the aggregation to match the question you are asking: Max exposes spikes, Avg shows typical load.

Azure Monitor: Metrics, Logs, Diagnostic Settings & Alerts (AZ-104) — the lesson that teaches this.

Question 3Monitor and maintain Azure resources

A company must analyze Azure Key Vault audit events with interactive KQL queries and correlate them with sign-in data already collected in the company's central Log Analytics workspace. The events are not collected by default. What should an administrator configure on the key vault?

Choose one.

  • a
    A diagnostic setting that sends the AuditEvent resource log category to the Log Analytics workspace Correct

    Resource logs are not collected until a diagnostic setting routes them to a destination. Sending the AuditEvent category to the workspace makes the events queryable with KQL alongside the existing data.

  • b
    A diagnostic setting that archives the AuditEvent category to a storage account

    A storage account destination provides cheap archival, but blobs of JSON are not interactively queryable with KQL and cannot be correlated with workspace tables.

  • c
    A metric alert rule on the key vault's availability metric

    A metric alert evaluates numeric metric values and fires notifications. It neither collects audit events nor makes them available for querying.

  • d
    An Azure Policy assignment that audits the key vault configuration

    Azure Policy evaluates resource configuration compliance. It does not route a resource's operational log events into a Log Analytics workspace.

The concept

Resource logs describe operations performed within an Azure resource, and they are discarded unless a diagnostic setting routes them to a Log Analytics workspace, a storage account, or an event hub. A Log Analytics workspace is the only destination that supports interactive KQL analysis.

Why that’s the answer

The scenario requires KQL queries and correlation with data already in a workspace, which only the Log Analytics destination provides; the diagnostic setting is the mechanism that starts collection. Storage-account archival stores the same events but offers no query engine, a metric alert monitors numbers rather than collecting events, and Azure Policy checks configuration compliance rather than routing operational logs.

How to reason it out
  1. Open the key vault and select Diagnostic settings under Monitoring.
  2. Add a diagnostic setting and select the AuditEvent log category.
  3. Choose Send to Log Analytics workspace, pick the central workspace, and save; then query the events with KQL.

Exam tip: Diagnostic settings turn on resource log collection, and Log Analytics is the destination to pick when you need KQL analysis.

Azure Monitor: Metrics, Logs, Diagnostic Settings & Alerts (AZ-104) — the lesson that teaches this.

Question 4Monitor and maintain Azure resources

A compliance policy requires that resource logs from several Azure firewalls be retained for seven years. The logs will almost never be read, and the solution must be the MOST cost-effective. Which diagnostic setting destination should an administrator choose?

Choose one.

  • a
    A Log Analytics workspace with long-term retention

    A workspace supports long retention, but you pay ingestion and retention charges designed for queryable data. For logs that are almost never read, that capability is wasted money compared with blob storage.

  • b
    An Azure Storage account Correct

    A storage account is the low-cost archival destination for diagnostic data. Combined with cool or archive access tiers and lifecycle management, it retains rarely accessed logs for years at minimal cost.

  • c
    An Azure Event Hub

    Event Hubs is a streaming pipeline that hands events to external consumers in near real time. It retains events only briefly and is not a long-term retention destination by itself.

  • d
    Application Insights

    Application Insights is an application performance monitoring feature for instrumented apps. It is not a diagnostic setting destination for firewall resource logs.

The concept

Diagnostic settings offer three main destinations with distinct purposes: Log Analytics workspace for interactive KQL analysis, storage account for cheap long-term archival, and event hub for streaming to external systems such as a third-party SIEM.

Why that’s the answer

Seven-year retention of logs that are rarely read is the textbook archival case, and the storage account destination is priced for exactly that, especially with cool or archive tiers. A workspace charges for ingestion and analytics capability the scenario never uses, an event hub retains data only briefly and exists to stream rather than store, and Application Insights is not a diagnostic destination at all.

How to reason it out
  1. Create or identify a storage account for log archival and consider cool or archive tier lifecycle rules.
  2. On each firewall, add a diagnostic setting selecting the required log categories.
  3. Choose Archive to a storage account as the destination and configure lifecycle management to meet the seven-year requirement.

Exam tip: For long-term, rarely accessed log retention, archive to a storage account; reserve Log Analytics for data you actually query.

Azure Monitor: Metrics, Logs, Diagnostic Settings & Alerts (AZ-104) — the lesson that teaches this.

Question 5Monitor and maintain Azure resources

A security team runs a third-party SIEM outside Azure and requires resource logs from production resources to be delivered to it in near real time as a continuous stream. Which diagnostic setting destination should an administrator configure?

Choose one.

  • a
    A Log Analytics workspace

    A workspace is the destination for analyzing logs inside Azure with KQL. It is a query store, not a push-based stream that an external SIEM consumes continuously.

  • b
    A storage account with lifecycle management

    Storage is a batch archival destination. The SIEM would have to poll blobs, which adds latency and engineering work rather than providing a native near-real-time stream.

  • c
    An action group with a webhook action

    Action groups deliver notifications when alert rules fire. They are not a diagnostic setting destination and cannot carry the full volume of resource log events.

  • d
    An Azure Event Hub Correct

    Event Hubs is the streaming destination for diagnostic data. External tools such as third-party SIEMs consume the event stream in near real time using standard event hub clients.

The concept

The event hub destination of a diagnostic setting exists to stream monitoring data out of Azure to external consumers - typically third-party SIEM and analytics platforms - with low latency.

Why that’s the answer

The requirement is a continuous near-real-time feed to an external system, which is precisely the event hub integration pattern. A Log Analytics workspace keeps data inside Azure for KQL analysis rather than pushing it out, a storage account delivers batched blobs that a SIEM must poll, and an action group is an alert notification mechanism, not a log transport.

How to reason it out
  1. Create an Event Hubs namespace and an event hub in the same region as the resources.
  2. Add a diagnostic setting on each production resource selecting the required log categories.
  3. Choose Stream to an event hub as the destination, then configure the SIEM's Azure connector to consume from that hub.

Exam tip: Stream to an event hub when monitoring data must leave Azure in near real time, such as to a third-party SIEM.

Azure Monitor: Metrics, Logs, Diagnostic Settings & Alerts (AZ-104) — the lesson that teaches this.

Question 6Monitor and maintain Azure resources

An administrator needs to determine which user deleted a network security group two days ago. No diagnostic settings were ever configured in the subscription. Where can the administrator find this information?

Choose one.

  • a
    Resource logs of the network security group

    Resource logs capture data-plane operations within a resource and require a diagnostic setting to be collected. A delete is a control-plane operation, and no diagnostic settings existed anyway.

  • b
    The Azure activity log Correct

    The activity log automatically records subscription-level control-plane operations, including who deleted a resource and when, and retains events for 90 days without any configuration.

  • c
    Azure Monitor metrics for the virtual network

    Metrics are numeric performance measurements. They contain no record of management operations or the identity that performed them.

  • d
    Network Watcher NSG flow logs

    Flow logs record allowed and denied network traffic through an NSG. They must be explicitly enabled and say nothing about who deleted the resource.

The concept

The activity log is the subscription-level record of control-plane (management) operations - create, update, delete, and role changes - captured automatically with 90 days of retention. Resource logs are data-plane records that exist only when a diagnostic setting collects them.

Why that’s the answer

Deleting an NSG is a control-plane write, so it appears in the activity log with the caller's identity and timestamp, and the two-day-old event is well within the 90-day window. Resource logs would not help even if configured because deletion is not a data-plane event, metrics carry no identity or operation records, and NSG flow logs describe traffic, not administrative actions.

How to reason it out
  1. Open Monitor in the Azure portal and select Activity log.
  2. Filter by the resource group or resource type Network security groups and set the time range to the last week.
  3. Locate the Delete Network Security Group operation and inspect the Event initiated by field for the user identity.

Exam tip: Who did what to a resource is always the activity log; what happened inside a resource is resource logs and needs a diagnostic setting.

Azure Monitor: Metrics, Logs, Diagnostic Settings & Alerts (AZ-104) — the lesson that teaches this.

What AZ-104 domain 5 tests, topic by topic

The official exam guide breaks Monitor and maintain Azure resources into 2 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published AZ-104 practice questions per topic in Monitor and maintain Azure resources
TopicWhat it coversQuestions
Monitor resources in AzureSkills outline section (AZ-104, as of April 17, 2026). Interpreting metrics in Azure Monitor; configuring log settings; querying and analyzing logs; setting up alert rules, action groups, and alert processing rules; configuring and interpreting monitoring of virtual machines, storage accounts, and networks by using Azure Monitor Insights; using Azure Network Watcher and Connection monitor.20
Implement backup and recoverySkills outline section (AZ-104, as of April 17, 2026). Creating a Recovery Services vault and an Azure Backup vault; creating and configuring a backup policy; performing backup and restore operations by using Azure Backup; configuring Azure Site Recovery for Azure resources; performing a failover to a secondary region; configuring and interpreting reports and alerts for backups.20
Total40

Revise Monitor and maintain Azure resources before you drill it

Other AZ-104 domains

Monitor and maintain Azure resources: your questions

Monitor and maintain Azure resources is domain 5 of the AZ-104 exam guide and carries 14% of the scored content — the lightest of the 5 domains. On a 50-question paper that works out to roughly 7 questions, though Microsoft Azure does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official AZ-104 exam guide.