Bird
Raised Fist0
Azurecloud~20 mins

Alerts and action groups in Azure - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Azure Alerts Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
❓ service_behavior
intermediate
2:00remaining
What happens when an Azure alert rule triggers?

An Azure alert rule is configured to monitor CPU usage above 80%. What is the immediate result when the CPU usage exceeds 80%?

AThe alert rule triggers and sends notifications to all linked action groups immediately.
BThe alert rule triggers but notifications are sent only after manual approval.
CThe alert rule triggers and automatically scales the VM without notifications.
DThe alert rule triggers but no action occurs unless a script is manually run.
Attempts:
2 left
💡 Hint

Think about how Azure alert rules and action groups work together to notify users.

❓ Configuration
intermediate
2:00remaining
Which JSON snippet correctly defines an Azure action group with an email receiver?

Choose the JSON snippet that correctly configures an Azure action group with an email receiver named 'OpsTeam'.

A{ "actionGroupName": "OpsAlertGroup", "email": [{ "receiver": "OpsTeam", "emailAddress": "ops@example.com" }] }
B{ "name": "OpsAlertGroup", "emailReceivers": [{ "email": "ops@example.com", "receiverName": "OpsTeam" }] }
C{ "name": "OpsAlertGroup", "emailReceivers": [{ "name": "OpsTeam", "emailAddress": "ops@example.com" }] }
D{ "groupName": "OpsAlertGroup", "receivers": [{ "type": "email", "name": "OpsTeam", "address": "ops@example.com" }] }
Attempts:
2 left
💡 Hint

Look for the correct property names used in Azure action group JSON schema.

❓ Architecture
advanced
3:00remaining
How to design alerting for multi-region Azure VMs with minimal notification delay?

You have VMs deployed in two Azure regions. You want alerts for high CPU usage to notify the on-call engineer with minimal delay and avoid duplicate alerts. Which design is best?

ACreate alert rules in each region but configure action groups to notify different engineers to avoid duplicates.
BCreate separate alert rules and action groups in each region, both notifying the same engineer email.
CUse only one region's alert rules and ignore the other region's metrics to reduce alerts.
DCreate a centralized Log Analytics workspace and alert rule aggregating metrics from both regions, linked to one action group.
Attempts:
2 left
💡 Hint

Think about centralizing monitoring to reduce duplicate alerts and delays.

❓ security
advanced
2:30remaining
What is the security risk of using a shared action group with multiple teams?

You configure one action group shared by multiple teams for alerts. What is a potential security risk of this setup?

AAction groups cannot be shared, so this setup will cause configuration errors.
BTeams may receive alerts irrelevant to their responsibilities, causing alert fatigue and possible ignoring of critical alerts.
CSharing action groups encrypts alert data, preventing teams from reading alerts.
DUsing shared action groups disables email notifications for all teams.
Attempts:
2 left
💡 Hint

Consider how alert relevance affects team response and security.

✅ Best Practice
expert
3:00remaining
How to implement automated remediation using Azure alerts and action groups?

You want to automatically restart a VM when a CPU alert triggers. Which action group configuration enables this automation?

AConfigure the action group with a webhook receiver that calls an Azure Function to restart the VM.
BConfigure the action group with an email receiver to notify the admin to restart the VM manually.
CConfigure the action group with an SMS receiver to alert the admin to restart the VM manually.
DConfigure the action group with a logic app receiver that sends a report but does not restart the VM.
Attempts:
2 left
💡 Hint

Think about how to trigger automated actions from alerts.

Practice

(1/5)
1. What is the main purpose of an alert in Azure Monitor?
easy
A. To create virtual machines automatically
B. To notify you when a specific condition occurs in your cloud resources
C. To store data backups securely
D. To manage user permissions in Azure

Solution

  1. Step 1: Understand what alerts monitor

    Alerts watch cloud resources and trigger when certain conditions happen, like high CPU or errors.
  2. Step 2: Identify alert purpose

    The main goal is to notify you so you can act quickly and keep systems healthy.
  3. Final Answer:

    To notify you when a specific condition occurs in your cloud resources -> Option B
  4. Quick Check:

    Alerts = Notifications on conditions [OK]
Hint: Alerts notify on issues; think 'watch and warn' [OK]
Common Mistakes:
  • Confusing alerts with resource creation
  • Thinking alerts manage backups
  • Assuming alerts control user access
2. Which of the following is the correct way to associate an action group with an alert rule in Azure?
easy
A. Create a new virtual network with the action group name
B. Add the action group as a tag to the resource
C. Specify the action group ID in the alert rule's actions section
D. Assign the action group to the resource's access control list

Solution

  1. Step 1: Review alert rule configuration

    Alert rules include an actions section where you specify which action groups to notify or trigger.
  2. Step 2: Confirm correct association method

    You link an action group by referencing its ID in the alert rule's actions, not by tags or network settings.
  3. Final Answer:

    Specify the action group ID in the alert rule's actions section -> Option C
  4. Quick Check:

    Action group linked via alert actions [OK]
Hint: Action groups go in alert actions, not tags or ACLs [OK]
Common Mistakes:
  • Trying to add action groups as resource tags
  • Confusing network setup with alert actions
  • Assigning action groups to access control lists
3. Given this alert rule JSON snippet, what action group will be triggered when the alert fires?
{
  "name": "HighCPUAlert",
  "criteria": {"metricName": "Percentage CPU", "threshold": 80},
  "actions": [{"actionGroupId": "/subscriptions/123/resourceGroups/rg1/providers/microsoft.insights/actionGroups/NotifyTeam"}]
}
medium
A. NotifyTeam
B. BackupGroup
C. ScaleUpGroup
D. SecurityAlertGroup

Solution

  1. Step 1: Locate action group ID in alert JSON

    The actions array contains an actionGroupId ending with 'NotifyTeam'.
  2. Step 2: Match action group name

    The ID clearly points to the 'NotifyTeam' action group, so this group triggers on alert.
  3. Final Answer:

    NotifyTeam -> Option A
  4. Quick Check:

    ActionGroupId ends with NotifyTeam [OK]
Hint: Look for actionGroupId value in alert JSON [OK]
Common Mistakes:
  • Picking wrong action group from unrelated names
  • Ignoring the actionGroupId field
  • Assuming default action group triggers
4. You created an alert rule but no notifications are sent when the condition is met. What is the most likely cause?
medium
A. The alert rule does not have any action groups assigned
B. The resource is offline
C. The alert rule threshold is set too low
D. The action group is disabled in Azure Security Center

Solution

  1. Step 1: Check alert rule configuration

    If no notifications are sent, first verify if the alert rule has action groups assigned to send alerts.
  2. Step 2: Understand action group role

    Action groups define who and how notifications are sent; without them, alerts trigger but no actions occur.
  3. Final Answer:

    The alert rule does not have any action groups assigned -> Option A
  4. Quick Check:

    No action groups = no notifications [OK]
Hint: Alerts need action groups to send notifications [OK]
Common Mistakes:
  • Assuming resource offline stops alerts
  • Thinking threshold affects notification sending
  • Confusing action group status with Security Center
5. You want to create an alert that sends an email and triggers an Azure Function when CPU usage exceeds 90%. Which setup correctly achieves this?
hard
A. Create an alert rule with a metric condition for CPU > 90%, and assign an action group with only Azure Function action
B. Create an alert rule with a log query for CPU > 90%, and assign an action group with only email action
C. Create an alert rule with a metric condition for CPU > 90%, but no action group is needed if you have an Azure Function
D. Create an alert rule with a metric condition for CPU > 90%, and assign an action group with email and Azure Function actions

Solution

  1. Step 1: Define alert condition and actions

    The alert must watch CPU metric > 90%, so use a metric condition. To notify and trigger automation, use an action group with both email and Azure Function actions.
  2. Step 2: Confirm action group capabilities

    Action groups can include multiple actions like email and Azure Functions, enabling combined notifications and automation.
  3. Final Answer:

    Create an alert rule with a metric condition for CPU > 90%, and assign an action group with email and Azure Function actions -> Option D
  4. Quick Check:

    Metric alert + action group with email & function [OK]
Hint: Use action group with all needed actions for alert [OK]
Common Mistakes:
  • Omitting action group when automation is needed
  • Using log query instead of metric for CPU
  • Assigning incomplete actions in action group