Preparing a subscription for Azure Monitor security alerts starts with creating a Log Analytics workspace as the data store

Configure and manage security monitoring and automation solutions
Answer Correct answer: C — Create a Log Analytics workspace first; Azure Monitor security alerts query data stored there.

Your company has an Azure subscription named Sub1. You plan to create several security alerts by using Azure Monitor. You need to prepare Sub1 for the alerts. What should you create first?

  1. an Azure Automation account
  2. an Azure event hub
  3. an Azure Log Analytics workspace Correct Answer
  4. an Azure Storage account

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A Log Analytics workspace is the foundational dependency for Azure Monitor alerting on logs; Automation accounts, Event Hubs, and Storage accounts are supporting or downstream services, not the first prerequisite.

Azure Monitor collects and analyzes log and metric data in a Log Analytics workspace. Before you can create security alerts from that data, you must first create a Log Analytics workspace, which becomes the backend store that the alert rules query.

Candidates pick Event Hub or Storage account, but those are for streaming/archive; the prerequisite for log-based security alerts in Azure Monitor is the Log Analytics workspace.

Community Discussion (3 comments)

243ccd6 👍 5
C. An Azure Log Analytics workspace
sudowhoami 👍 1 Selected: C
C is correct.
Jimmy500 👍 1
C is the an answer , as Monitor works on Log Analytics workspace

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure Monitor log alerts query data stored in a Log Analytics workspace. To prepare the subscription for security alerts, you first create a Log Analytics workspace, which is the data store the alert rules depend on. (Option C)

Why the Other Options Are Wrong

  • Option A (Automation account) is for runbooks/process automation, not the log store for alerts.
  • Option B (Event Hub) is for streaming telemetry to external consumers, not the alert data source.
  • Option D (Storage account) is for long-term blob/archive, not the queryable store Azure Monitor alerts use.

Community Comment Notes

Comments confirmed C, noting 'Monitor works on Log Analytics workspace' and that the workspace is the prerequisite for the alerts.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide