exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 5 question 6 discussion

Actual exam question from Microsoft's AZ-104
Question #: 6
Topic #: 5
[All AZ-104 Questions]

HOTSPOT -
You have an Azure virtual network named VNet1 that connects to your on-premises network by using a site-to-site VPN. VNet1 contains one subnet named
Sunet1.
Subnet1 is associated to a network security group (NSG) named NSG1. Subnet1 contains a basic internal load balancer named ILB1. ILB1 has three Azure virtual machines in the backend pool.
You need to collect data about the IP addresses that connects to ILB1. You must be able to run interactive queries from the Azure portal against the collected data.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: An Azure Log Analytics workspace
In the Azure portal you can set up a Log Analytics workspace, which is a unique Log Analytics environment with its own data repository, data sources, and solutions

Box 2: ILB1 -
Reference:
https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-quick-create-workspace https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-standard-diagnostics

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mlantonis
Highly Voted 3 years, 9 months ago
Correct Answer: Box 1: An Azure Log Analytics workspace In the Azure portal you can set up a Log Analytics workspace, which is a unique Log Analytics environment with its own data repository, data sources, and solutions. Box 2: NSG1 NSG flow logs allow viewing information about ingress and egress IP traffic through a Network security group. Through this, the IP addresses that connect to the ILB can be monitored when the diagnostics are enabled on a Network Security Group. We cannot enable diagnostics on an internal load balancer to check for the IP addresses. As for Internal LB, it is basic one. Basic can only connect to storage account. Also, Basic LB has only activity logs, which doesn't include the connectivity workflow. So, we need to use NSG to meet the mentioned requirements.
upvoted 255 times
awssecuritynewbie
2 years, 5 months ago
very good catch! Because yes you are right after looking at the link : https://learn.microsoft.com/en-gb/azure/load-balancer/skus#skus you cannot do diagnostics for the load balancer you know, which is crazy i would of picked that over the NSG. Box 2: NSG1
upvoted 10 times
...
mlantonis
3 years, 9 months ago
Reference: https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-quick-create-workspace https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-standard-diagnostics
upvoted 25 times
...
elrizos
1 year, 10 months ago
you r my hero
upvoted 3 times
...
Indy429
1 year, 2 months ago
I was about to say "why is the second one not NSG1?" Glad you confirmed NSG1 is the right answer for Q2.
upvoted 1 times
...
...
fedztedz
Highly Voted 4 years, 2 months ago
Answer is not correct. The correct answer is - Create a Log Analytics Workspace - NSG As for Internal LB, it is basic one. Basic can only connect to storage account. Also Basic LB has only activity logs which doesn't include the connectivity workflow. So, we need to use NSG to meet the mentioned requirements.
upvoted 96 times
Josh219
3 months, 1 week ago
correct Box 1: An Azure Log Analytics workspace Box 2: NSG1
upvoted 1 times
...
Alvaroll
4 years, 1 month ago
I think the answer given is correct. - Azure Log Analytics workspace - ILB1 (Standard Load Balance) https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-monitor-log
upvoted 4 times
Alvaroll
4 years, 1 month ago
sorry, it's basic LB
upvoted 6 times
...
...
YooOY
3 years, 5 months ago
Basic LB no diagnositcs https://docs.microsoft.com/en-us/azure/load-balancer/skus
upvoted 3 times
...
s9p3r7
3 years, 8 months ago
but you can't enable NSG flow logs with Log Analytics Workspace, you need a storage account. answer: storage acc and nsg ref: https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-portal#enable-nsg-flow-log
upvoted 4 times
s9p3r7
3 years, 8 months ago
ignore my previous comment as Traffic Analytics can be integrated with Log Analytics Workspace,,
upvoted 6 times
...
...
...
[Removed]
Most Recent 5 months, 1 week ago
WRONG An Azure Log Analytics workspace NSG1
upvoted 3 times
...
tashakori
11 months, 3 weeks ago
Given answer is correct
upvoted 1 times
...
1828b9d
1 year ago
This question was in exam 01/03/2024
upvoted 4 times
...
Josete1106
1 year, 7 months ago
B&B is correct!
upvoted 1 times
...
stonwall12
1 year, 8 months ago
1. Azure Log Analytics 2. NSG1 Note: Internal Balancer is only BASIC
upvoted 1 times
...
shadad
1 year, 12 months ago
I took Exam of Azure- 104 at 27/2/2023 I score 920 points out of 1000 points. This was on it and my answer was: Box1: An Azure Log Analytics workspace Box2: Box 2: NSG1
upvoted 8 times
...
vbohr899
2 years ago
Cleared Exam today 26 Feb, This question was there in exam.
upvoted 4 times
...
CyberKelev
2 years ago
To collect data about the IP addresses that connect to ILB1 and run interactive queries from the Azure portal against the collected data, you should create an Azure Log Analytics workspace. You should enable diagnostic settings on ILB1. This will allow you to collect data about the IP addresses that connect to ILB1 and run interactive queries from the Azure portal against the collected data.
upvoted 1 times
...
Ashfaque_9x
2 years, 1 month ago
Passed today on 29Jan23 with a score of 970. This question was in the exam. Correct Answer: Box 1: An Azure Log Analytics workspace Box 2: NSG1
upvoted 5 times
...
djgodzilla
2 years, 1 month ago
I think it's good to pause and watch a video describing the available monitoring service for standard Load balancer (classic metrics view vs load balancer insights). It'll allow you to understand instead of just picking an answer . guess basic has no monitoring feature satisfying the question's requirement. https://www.youtube.com/watch?v=qfzOTNKYTgU&ab_channel=MicrosoftAzure
upvoted 2 times
...
Liriano
2 years, 4 months ago
In exam today, go with highly voted
upvoted 3 times
...
EmnCours
2 years, 6 months ago
An azure log analytics workspace NSG1
upvoted 1 times
...
Lazylinux
2 years, 8 months ago
given answer not correct Box 1: An Azure Log Analytics workspace use Log Analytics workspace, which sets Log Analytics environment with its own data repository, data sources, and solutions. Box 2: NSG1 NSG flow logs, which provide you information about ingress and egress IP traffic through a Network Security Group associated to individual network interfaces, VMs, or subnets. By analyzing raw NSG flow logs, and inserting intelligence of security, topology, and geography, traffic analytics can provide you with insights into traffic flow in your environment. Traffic Analytics provides information such as most communicating hosts, most communicating application protocols, most conversing host pairs, allowed/blocked traffic, inbound/outbound traffic, open internet ports, most blocking rules, traffic distribution per Azure datacenter, virtual network, subnets, or, rogue networks.
upvoted 3 times
...
Akman
3 years, 4 months ago
I'm tired of entering capcha in every page turn
upvoted 6 times
verifedtomic
3 years, 3 months ago
Just sign-up for free account. Then you'll have to enter captcha every three or so pages.
upvoted 3 times
...
nzmike
3 years, 3 months ago
that's why they have the subscription...
upvoted 9 times
...
...
khengoolman
3 years, 4 months ago
Passed 11 Oct 2021 with 947. This question appeared, correct Answer is LAW, NSG
upvoted 11 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago