AZ-104 monitoring and backup explained

Updated September 28, 2026

Monitor and maintain Azure resources is the smallest AZ-104 domain at 10–15%, but its questions are among the most predictable on the exam. It covers two areas: monitoring with Azure Monitor and Network Watcher, and backup and recovery with Azure Backup and Azure Site Recovery. If you know which tool answers which question, most of this domain is quick marks.

Monitor resources in Azure

Metrics and logs

Azure Monitor collects two kinds of data:

MetricsLogs
WhatNumeric values at regular intervalsRecords with many fields
ExamplesCPU percentage, disk IOPS, transactionsActivity log, resource logs, VM events
WhereMetrics database, collected automatically for most resourcesLog Analytics workspace
Query withMetrics explorerKQL in Log Analytics

Platform metrics arrive without configuration. Resource logs do not: you create a diagnostic setting on the resource and send them to a Log Analytics workspace, a storage account or an event hub. The activity log records control plane operations — who created, changed or deleted what — at subscription level.

Querying logs

You do not need to be a KQL expert, but you should read simple queries. The shape is always the same: a table, then filters, then aggregation.

AzureActivity
| where TimeGenerated > ago(7d)
| where OperationNameValue endswith "DELETE"
| summarize count() by Caller

Know where, summarize ... by, bin(), project, order by and render.

Alerts

An alert has three parts, and the exam likes to test which part solves which problem:

  • An alert rule defines the signal and condition: a metric threshold, a log search query or an activity log event.
  • An action group defines who is notified and what runs: email, SMS, push, voice, webhook, Automation runbook, Function or Logic App. One action group can serve many rules.
  • An alert processing rule changes what happens to fired alerts at scale: suppress notifications during a maintenance window, or add an action group to every alert in a subscription.

“Stop notifications during planned maintenance without disabling rules” is an alert processing rule.

Insights

VM insights shows performance and dependency maps for VMs and needs the Azure Monitor Agent with a data collection rule. Storage insights and network insights give ready-made workbooks across many accounts or networks without setup.

Network Watcher and Connection monitor

Network Watcher is enabled per region. Its tools include IP flow verify, next hop, NSG diagnostics, packet capture and connection troubleshoot. Connection monitor runs continuous tests between endpoints — VMs, on-premises machines or URLs — and alerts when latency or reachability degrades.

Implement backup and recovery

Two kinds of vault

The outline names both, so know which workload goes where:

VaultProtects
Recovery Services vaultAzure VMs, SQL Server and SAP HANA in VMs, Azure Files, on-premises through the MARS agent; also hosts Site Recovery
Backup vaultNewer workloads such as Azure Disks, Azure Blobs and Azure Database for PostgreSQL

A vault must be in the same region as the resources it backs up.

Backup policies

A policy sets the schedule (daily or more often, depending on the policy type) and retention for daily, weekly, monthly and yearly points. Changing a policy affects every item that uses it. VM backups start with a snapshot kept locally for fast restore, then transfer to the vault.

Backup and restore operations

For a VM you can restore a new VM, replace the disks of an existing one, restore disks only, or recover individual files by mounting a recovery point. Soft delete keeps deleted backup data for a period, which protects against someone stopping protection and deleting the data.

Azure Site Recovery

Site Recovery replicates VMs continuously to a secondary region. The sequence the exam expects:

  1. Enable replication for the VMs to the target region.
  2. Run a test failover into an isolated network to prove it works without affecting production.
  3. During a real outage, run a failover and then commit it.
  4. Re-protect to replicate back, and later fail back.

Recovery plans group VMs and set the order they start in, for example database before web tier.

Backup and Site Recovery are not interchangeable. Backup is for restoring data to a point in time; Site Recovery is for keeping a workload running in another region.

Reports and alerts for backups

Backup reports need a diagnostic setting on the vault that sends data to a Log Analytics workspace. Built-in alerts for backup failures come through Azure Monitor and can use action groups like any other alert.

Sample questions

Question 1. Every Sunday night between 22:00 and 02:00 the operations team patches servers. During that window, alerts should still fire and be recorded, but nobody should be emailed or paged. What should you create?

  • A. Disable all alert rules each Sunday with a runbook
  • B. Delete the action groups and recreate them on Monday
  • C. An alert processing rule that suppresses notifications on a schedule
  • D. A diagnostic setting that sends alerts to a storage account
Show answer

Answer: C

An alert processing rule can suppress action group notifications for a scheduled window while the alerts still fire and remain visible. Disabling the alert rules stops alerts entirely. Deleting action groups breaks every rule that uses them. A diagnostic setting routes logs and does not affect notifications.

Want more questions like this? Full AZ-104 practice tests →

Question 2. You need to see which user deleted a virtual machine three days ago. No diagnostic settings have been configured. Where should you look?

  • A. The subscription’s activity log
  • B. The VM’s CPU metrics in Metrics explorer
  • C. VM insights for the deleted VM
  • D. The VM’s resource logs in Log Analytics
Show answer

Answer: A

The activity log records control plane operations, including deletes and who performed them, at subscription level without any configuration. Metrics hold numeric performance data, VM insights needs an agent and shows performance, and resource logs require a diagnostic setting that was never created.

Want more questions like this? Full AZ-104 practice tests →

Question 3. Critical VMs in West Europe must be able to run in North Europe within minutes if West Europe becomes unavailable. You must prove the setup works without affecting production. What should you do?

  • A. Configure daily VM backups to a Recovery Services vault in West Europe
  • B. Take daily managed disk snapshots
  • C. Switch the VMs’ storage to geo-redundant storage
  • D. Enable Site Recovery replication to North Europe and run a test failover
Show answer

Answer: D

Site Recovery replicates the VMs to North Europe, and a test failover into an isolated network proves recovery without touching production. Azure Backup restores to a point in time and is slower to bring a workload up in another region. A snapshot schedule and geo-redundant storage alone do not give you running VMs or a tested failover.

Want more questions like this? Full AZ-104 practice tests →

What to practise

Send a VM’s logs to a Log Analytics workspace, write a query, and build a metric alert with an action group that emails you. Add an alert processing rule and check that it silences the email. Back up the VM to a Recovery Services vault, restore one file, then replicate it with Site Recovery to another region and run a test failover. Clean up afterwards: replicated VMs and vaults with backup data keep costing money.