nerdexam
Microsoft

AZ-500 · Question #208

You are collecting events from Azure virtual machines to an Azure Log Analytics workspace. You plan to create alerts based on the collected events. You need to identify which Azure services can be…

The correct answer is A. Azure Monitor D. Azure Sentinel. To create alerts based on events collected from Azure VMs in a Log Analytics workspace, you should identify Azure Monitor and Azure Sentinel.

Submitted by kavita_s· Mar 6, 2026Implement an instrumentation strategy

Question

You are collecting events from Azure virtual machines to an Azure Log Analytics workspace. You plan to create alerts based on the collected events. You need to identify which Azure services can be used to create the alerts. Which two services should you identify? Each correct answer presents a complete solution NOTE: Each correct selection is worth one point.

Options

  • AAzure Monitor
  • BAzure Security Center
  • CAzure Analytics Services
  • DAzure Sentinel
  • EAzure Advisor

How the community answered

(30 responses)
  • A
    80% (24)
  • B
    10% (3)
  • C
    7% (2)
  • E
    3% (1)

Why each option

To create alerts based on events collected from Azure VMs in a Log Analytics workspace, you should identify Azure Monitor and Azure Sentinel.

AAzure MonitorCorrect

Azure Monitor is the primary service for collecting, analyzing, and acting on telemetry from Azure and on-premises environments, including creating alerts based on log data from Log Analytics workspaces.

BAzure Security Center

Microsoft Defender for Cloud (formerly Azure Security Center) provides security posture management and threat protection, primarily generating its own security alerts rather than being the direct platform for creating custom alerts from raw Log Analytics events for general monitoring.

CAzure Analytics Services

Azure Analytics Services is a general term for various data analytics platforms and is not specifically designed for creating operational alerts from Log Analytics workspace data.

DAzure SentinelCorrect

Azure Sentinel is a Security Information and Event Management (SIEM) solution built on Azure Log Analytics, which allows you to create analytics rules (alerts) based on ingested security data and events.

EAzure Advisor

Azure Advisor provides personalized recommendations for optimizing Azure resources, but it is not used to create alerts from log data.

Concept tested: Alerting from Log Analytics with Azure Monitor and Sentinel

Source: https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/alerts-unified-log, https://learn.microsoft.com/en-us/azure/sentinel/detect-threats-built-in

Topics

#Azure Monitor#Azure Sentinel#alerts#Log Analytics

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice