Common Pitfalls to Avoid
-
Metrics vs Logs
-
Metrics = near real-time, numbers (CPU %, requests/sec).
-
Logs = detailed, searchable events (sign-ins, errors).
-
Exam trap: “Analyze 30 days of failed logins” → Logs (Log Analytics), not Metrics.
-
-
Activity Log vs Resource Log
-
Activity Log = subscription-level actions (who created/deleted a VM).
-
Resource Log = inside the resource (SQL queries, firewall traffic).
-
Exam trap: “Find who deleted a VM” → Activity Log.
-
-
Alert vs Action Group
-
Alert = detects condition.
-
Action Group = what happens next (email, automation).
-
Exam trap: “Alerts send SMS directly” → False, they need Action Groups.
-
-
Snapshot vs Backup vs ASR
-
Snapshot = point-in-time copy of a disk (crash-consistent).
-
Backup = long-term, scheduled, application-consistent (Recovery Services Vault).
-
ASR = replication & failover for disaster recovery.
-
Exam trap: “Retain backups for 90 days” → Backup, not snapshot.
-
Exam trap: “Failover to another region” → ASR, not Backup.
-
Quick Recall Hacks
-
“Real-time CPU monitoring” → Metrics
-
“Search logs over 30 days” → Log Analytics + KQL
-
“Alert someone + trigger automation” → Action Groups
-
“Compliance-driven long-term retention” → Recovery Services Vault
-
“One-time rollback before patching” → Snapshot
-
“Keep workloads running during regional outage” → ASR
What to Expect in the Exam
-
Direct questions on Metrics vs Logs, Backup vs Snapshot vs ASR.
-
Scenario-based questions like setting alerts, using KQL, or monitoring VM performance.
-
Compliance-related questions around backup retention and recovery policies.
-
Disaster recovery scenarios testing ASR knowledge.
Final Exam Strategy
-
Identify the data type: Metrics (numbers) or Logs (events).
-
Check retention requirement: Snapshot (short-term) vs Backup (long-term).
-
Check recovery requirement: Backup (restore data) vs ASR (failover workloads).
-
Watch for automation cues: If the scenario mentions “notify” or “trigger action,” it involves Alerts + Action Groups.