Bird
Raised Fist0
Azurecloud~20 mins

Diagnostic settings for resources in Azure - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Diagnostic Settings Mastery
Get all challenges correct to earn this badge!
Test your skills under time pressure!
❓ Configuration
intermediate
2:00remaining
Identify the correct diagnostic setting configuration to send logs to a Log Analytics workspace
Which of the following JSON snippets correctly configures diagnostic settings for an Azure resource to send logs and metrics to a Log Analytics workspace?
A
{
  "properties": {
    "workspaceId": "/subscriptions/xxxx/resourceGroups/rg1/providers/Microsoft.OperationalInsights/workspaces/logAnalytics1",
    "logs": [
      { "category": "AuditLogs", "enabled": true }
    ],
    "metrics": [
      { "category": "AllMetrics", "enabled": true }
    ]
  }
}
B
{
  "properties": {
    "logAnalyticsWorkspaceId": "/subscriptions/xxxx/resourceGroups/rg1/providers/Microsoft.OperationalInsights/workspaces/logAnalytics1",
    "logs": [
      { "category": "AuditLogs", "enabled": true }
    ],
    "metrics": [
      { "category": "AllMetrics", "enabled": true }
    ]
  }
}
C
{
  "properties": {
    "workspaceId": "/subscriptions/xxxx/resourceGroups/rg1/providers/Microsoft.OperationalInsights/workspaces/logAnalytics1",
    "logs": [
      { "category": "AuditLogs", "enabled": false }
    ],
    "metrics": [
      { "category": "AllMetrics", "enabled": true }
    ]
  }
}
D
}
}  
]    
} eurt :"delbane" ,"scirteMllA" :"yrogetac" {      
[ :"scirtem"    
,]    
} eurt :"delbane" ,"sgoLtiduA" :"yrogetac" {      
[ :"sgol"    
,"1scitylanAgol/secapskrow/sthgisnIlanoitarepO.tfosorciM/sredivorp/1gr/spuorGecruoser/xxxx/snoitpircsbus/" :"dIecapskrow"    
{ :"seitreporp"  
{
Attempts:
2 left
💡 Hint
Look for the correct property name for the Log Analytics workspace and ensure logs are enabled.
❓ service_behavior
intermediate
1:30remaining
Effect of missing retention policy in diagnostic settings
What happens if you configure diagnostic settings for an Azure resource without specifying a retention policy for logs?
ALogs are automatically deleted after 30 days by default.
BLogs are retained for 90 days by default.
CLogs are retained indefinitely until manually deleted.
DLogs are not collected at all without a retention policy.
Attempts:
2 left
💡 Hint
Think about default behavior when retention is not set.
❓ security
advanced
2:30remaining
Securing diagnostic settings data flow
Which configuration ensures that diagnostic logs sent from an Azure resource to a storage account are encrypted and access is restricted?
ADisable encryption but restrict access with firewall rules to trusted IPs only.
BUse a public storage account with no encryption and allow all networks to access it.
CUse customer-managed keys without network restrictions on the storage account.
DEnable storage account encryption with Microsoft-managed keys and configure a private endpoint for the storage account.
Attempts:
2 left
💡 Hint
Consider both encryption and network access controls.
❓ Architecture
advanced
3:00remaining
Designing diagnostic settings for multi-region resource monitoring
You have resources deployed in multiple Azure regions. What is the best approach to centralize diagnostic logs for monitoring and analysis?
ACreate separate Log Analytics workspaces in each region and keep logs isolated per region.
BConfigure each resource to send diagnostic logs to a single Log Analytics workspace in one region.
CSend logs to storage accounts in each region without central aggregation.
DUse Event Hubs to stream logs to an on-premises SIEM system only.
Attempts:
2 left
💡 Hint
Think about ease of analysis and cost efficiency.
🧠 Conceptual
expert
2:30remaining
Understanding diagnostic settings limits and impact
What is the maximum number of diagnostic settings you can configure per Azure resource, and what happens if you exceed this limit?
AYou can configure up to 5 diagnostic settings per resource; attempts to add more will fail with a quota error.
BThere is no limit on diagnostic settings per resource; Azure automatically manages scaling.
CYou can configure up to 10 diagnostic settings per resource; exceeding this causes logs to be dropped silently.
DOnly 1 diagnostic setting is allowed per resource; additional settings overwrite the existing one.
Attempts:
2 left
💡 Hint
Check Azure resource limits documentation for diagnostic settings.

Practice

(1/5)
1. What is the main purpose of Diagnostic settings in Azure resources?
easy
A. To collect logs and metrics for monitoring and troubleshooting
B. To create virtual machines automatically
C. To manage user access permissions
D. To deploy web applications

Solution

  1. Step 1: Understand diagnostic settings role

    Diagnostic settings collect logs and metrics from Azure resources to help monitor and troubleshoot.
  2. Step 2: Compare options with purpose

    Options A, B, and C describe other Azure features unrelated to diagnostics.
  3. Final Answer:

    To collect logs and metrics for monitoring and troubleshooting -> Option A
  4. Quick Check:

    Diagnostic settings = collect logs and metrics [OK]
Hint: Diagnostic settings always collect logs and metrics [OK]
Common Mistakes:
  • Confusing diagnostic settings with access control
  • Thinking diagnostic settings deploy resources
  • Assuming diagnostic settings manage applications
2. Which of the following is the correct way to specify a diagnostic setting destination in Azure CLI?
easy
A. az network watcher configure --name MyDiag --resource MyResource --workspace MyWorkspace
B. az vm create --name MyDiag --resource MyResource --workspace MyWorkspace
C. az storage account create --name MyDiag --resource MyResource --workspace MyWorkspace
D. az monitor diagnostic-settings create --name MyDiag --resource MyResource --workspace MyWorkspace

Solution

  1. Step 1: Identify correct Azure CLI command for diagnostic settings

    The command az monitor diagnostic-settings create is used to create diagnostic settings.
  2. Step 2: Verify other commands

    Commands for VM, storage account, and network watcher do not create diagnostic settings.
  3. Final Answer:

    az monitor diagnostic-settings create --name MyDiag --resource MyResource --workspace MyWorkspace -> Option D
  4. Quick Check:

    Diagnostic settings use az monitor diagnostic-settings create [OK]
Hint: Use 'az monitor diagnostic-settings create' to configure diagnostics [OK]
Common Mistakes:
  • Using VM or storage commands instead of monitor diagnostic-settings
  • Confusing resource creation with diagnostic configuration
  • Missing required parameters for diagnostic settings
3. Given this Azure CLI command:
az monitor diagnostic-settings create --name Diag1 --resource /subscriptions/123/resourceGroups/rg1/providers/Microsoft.Compute/virtualMachines/vm1 --workspace ws1 --logs '[{"category": "Administrative", "enabled": true}]'

What will this command do?
medium
A. Create a new virtual machine named Diag1
B. Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1
C. Disable all logs for the virtual machine vm1
D. Send metrics only to storage account ws1

Solution

  1. Step 1: Analyze command parameters

    The command creates diagnostic settings named Diag1 for VM vm1, sending logs to workspace ws1, enabling Administrative logs.
  2. Step 2: Interpret log category and destination

    Logs category "Administrative" is enabled and sent to Log Analytics workspace ws1.
  3. Final Answer:

    Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1 -> Option B
  4. Quick Check:

    Diagnostic settings send logs to workspace = Enable Administrative logs to be sent to Log Analytics workspace ws1 for VM vm1 [OK]
Hint: Look for --logs and --workspace to identify log destination [OK]
Common Mistakes:
  • Thinking it creates a VM instead of diagnostic settings
  • Confusing logs with metrics or storage
  • Assuming logs are disabled
4. You tried to create a diagnostic setting with this command:
az monitor diagnostic-settings create --name Diag2 --resource /subscriptions/123/resourceGroups/rg1/providers/Microsoft.Storage/storageAccounts/sa1 --storage-account sa1 --metrics '[{"category": "AllMetrics", "enabled": true}]'

But you get an error. What is the most likely cause?
medium
A. Diagnostic settings cannot send metrics to storage accounts
B. The metrics category "AllMetrics" is invalid
C. The storage account name is missing or incorrect
D. The resource ID format is wrong

Solution

  1. Step 1: Understand diagnostic settings destinations

    Diagnostic settings can send logs and metrics to Log Analytics, Storage, or Event Hub. The --storage-account parameter requires the full ARM resource ID of the storage account.
  2. Step 2: Check command parameters

    The command specifies --storage-account sa1, which is only the short name and cannot be resolved by the CLI.
  3. Final Answer:

    The storage account name is missing or incorrect -> Option C
  4. Quick Check:

    --storage-account requires full ID [OK]
Hint: Use full ARM ID for --storage-account [OK]
Common Mistakes:
  • Using short name instead of full resource ID for --storage-account
  • Thinking metrics cannot be sent to storage accounts
  • Assuming invalid metrics category or wrong resource ID
5. You want to monitor an Azure SQL Database and send both logs and metrics to a Log Analytics workspace. Which combination of diagnostic settings configuration is correct?
hard
A. Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace
B. Enable only logs categories and send to Storage account
C. Enable metrics only and send to Event Hub
D. Enable logs and metrics but send logs to Storage and metrics to Log Analytics workspace

Solution

  1. Step 1: Identify correct log and metric categories for Azure SQL Database

    Logs like 'SQLSecurityAuditEvents' and 'SQLInsights' and metrics 'AllMetrics' are valid categories for Azure SQL Database diagnostics.
  2. Step 2: Confirm destination for logs and metrics

    Both logs and metrics can be sent to Log Analytics workspace for monitoring and analysis.
  3. Final Answer:

    Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace -> Option A
  4. Quick Check:

    Logs and metrics to Log Analytics = Enable logs categories 'SQLSecurityAuditEvents' and 'SQLInsights' and enable metrics category 'AllMetrics' with destination set to Log Analytics workspace [OK]
Hint: Send both logs and metrics to Log Analytics for full monitoring [OK]
Common Mistakes:
  • Sending logs to storage but metrics elsewhere
  • Enabling only logs or only metrics
  • Using wrong categories for Azure SQL Database