exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 2 question 89 discussion

Actual exam question from Microsoft's AZ-700
Question #: 89
Topic #: 2
[All AZ-700 Questions]

You have an Azure subscription that contains 100 network security groups (NSGs).

You need to ensure that you log the application of specific NSG rules.

Which type of log should you configure?

  • A. flow log
  • B. activity log
  • C. Azure resource log
  • D. audit log
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
e6d6bf4
Highly Voted 4 months, 3 weeks ago
Selected Answer: C
https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-nsg-manage-log The question is asking to enable logging to collect rules applies to traffic that got blocked or allow. Answer is C. Azure Resource Log "A network security group (NSG) includes rules that allow or deny traffic to a virtual network subnet, network interface, or both. When you enable logging for an NSG, you can gather the following types of resource log information: Event: Entries are logged for which NSG rules are applied to virtual machines, based on a MAC address. Rule counter: Contains entries for how many times each NSG rule is applied to allow or deny traffic. The status for these rules is collected every 300 seconds."
upvoted 7 times
e6d6bf4
3 months, 3 weeks ago
I stand corrected - -> the correct answer is Flow Log as we just want to identify the application logs that got the NGS rules. We don't need the diagnose in-depth data.
upvoted 2 times
...
...
marcin1999
Most Recent 1 week, 3 days ago
Selected Answer: C
100% c
upvoted 1 times
...
ITrob523
2 weeks ago
Selected Answer: C
It's for the "application" of the NSG rules. Which would be Azure Resource Logs. It's not asking for traffic flow... It's asking about knowing when or who applied an NSG which would be resource logs. Don't be fooled by the trick wording here.
upvoted 1 times
...
tc0369
2 weeks, 6 days ago
Selected Answer: C
Should be C. Keyword- the question is asking "the specific NSG Rules"! Flow log only gives allow or deny by a NSG, but not tell which rule under NSG hit.
upvoted 1 times
...
gaurav4101
3 months, 3 weeks ago
Selected Answer: A
Flow logs is correct. ----------------------- Identify unknown or undesired traffic. Monitor traffic levels and bandwidth consumption. Filter flow logs by IP and port to understand application behavior. Export flow logs to analytics and visualization tools of your choice to set up monitoring dashboards. https://learn.microsoft.com/en-us/azure/network-watcher/nsg-flow-logs-overview#common-use-cases ================== Azure resource logs are platform logs that provide insight into operations that are performed in an Azure resource. https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/resource-logs
upvoted 3 times
...
manhattan
4 months ago
Selected Answer: A
I don't think you need something fancy here, just port and protocol to identify the application logs with trhe regular Azure NSG flow logs. https://learn.microsoft.com/en-us/azure/network-watcher/nsg-flow-logs-overview#common-use-cases Common use cases: Filter flow logs by IP and port to understand application behavior.
upvoted 3 times
...
alexastein
4 months ago
Selected Answer: A
https://learn.microsoft.com/en-us/azure/network-watcher/nsg-flow-logs-overview
upvoted 3 times
...
ashaw20
4 months, 1 week ago
Selected Answer: A
Flow logs collects ingress/egress IP packets which flows through your NSG (primary objective is to analyze network traffic). Azure Resource logs provides Diagnostics log as it contains higher-level abstraction of log entity i.e. they provide log details are tenant/resource group (or resources) scope. Flow logs is the correct answer since we need to ensure the application of the NSG rules. We don't need to diagnose in details.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago