exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 5 question 47 discussion

Actual exam question from Microsoft's AZ-104
Question #: 47
Topic #: 5
[All AZ-104 Questions]

HOTSPOT -
You plan to use Azure Network Watcher to perform the following tasks:
✑ Task1: Identify a security rule that prevents a network packet from reaching an Azure virtual machine.
✑ Task2: Validate outbound connectivity from an Azure virtual machine to an external host.
Which feature should you use for each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: IP flow verify -
At some point, a VM may become unable to communicate with other resources, because of a security rule. The IP flow verify capability enables you to specify a source and destination IPv4 address, port, protocol (TCP or UDP), and traffic direction (inbound or outbound). IP flow verify then tests the communication and informs you if the connection succeeds or fails. If the connection fails, IP flow verify tells you which.

Box 2: Connection troubleshoot -
Diagnose outbound connections from a VM: The connection troubleshoot capability enables you to test a connection between a VM and another VM, an FQDN, a
URI, or an IPv4 address. The test returns similar information returned when using the connection monitor capability, but tests the connection at a point in time, rather than monitoring it over time, as connection monitor does. Learn more about how to troubleshoot connections using connection-troubleshoot.
Reference:
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mlantonis
Highly Voted 3 years, 9 months ago
Correct Answer: Box 1: IP flow verify At some point, a VM may become unable to communicate with other resources, because of a security rule. The IP flow verify capability enables you to specify a source and destination IPv4 address, port, protocol (TCP or UDP), and traffic direction (inbound or outbound). IP flow verify then tests the communication and informs you if the connection succeeds or fails. If the connection fails, IP flow verify tells you which. Box 2: Connection troubleshoot Diagnose outbound connections from a VM: The connection troubleshoot capability enables you to test a connection between a VM and another VM, an FQDN, a URI, or an IPv4 address. The test returns similar information returned when using the connection monitor capability, but tests the connection at a point in time, rather than monitoring it over time, as connection monitor does. Learn more about how to troubleshoot connections using connection-troubleshoot.
upvoted 152 times
Holydud
2 years, 6 months ago
Was on exam 19 Aug 2022. Scored 870. Around 85% questions were also on ET. Answered: Box1: IP flow verify Box2: Connection troubleshoot
upvoted 13 times
Kem81
2 years, 5 months ago
thanks for confirming. I'll be sitting the exam at the end of October.
upvoted 5 times
Babushka
2 years, 4 months ago
How did it go?
upvoted 2 times
...
...
...
...
mdyck
Highly Voted 3 years, 10 months ago
IP Flow Verify "You might override Azure's default rules, or create additional rules. At some point, a VM may become unable to communicate with other resources, because of a security rule. IP flow verify then tests the communication and informs you if the connection succeeds or fails." https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview#diagnose-network-traffic-filtering-problems-to-or-from-a-vm Connection Troubleshoot "The connection troubleshoot capability enables you to test a connection between a VM and another VM, an FQDN, a URI, or an IPv4 address" https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview#connection-troubleshoot
upvoted 20 times
...
[Removed]
Most Recent 5 months, 1 week ago
CORRECT
upvoted 3 times
...
Ni22
8 months, 3 weeks ago
6/13/24 on exam
upvoted 3 times
...
23169fd
9 months ago
The given answer is correct. Ip Flow Verify: The IP flow verify feature allows you to determine if a packet is allowed or denied based on the configured NSG rules Connection Troubleshoot: diagnose connectivity issues from a VM to an external endpoint.
upvoted 1 times
...
18c2076
11 months, 2 weeks ago
I know it isnt an option, but you could also use Connection Monitor for this as well...
upvoted 1 times
18c2076
11 months, 2 weeks ago
Nevermind, I lied. Connection Monitor is for internal or hybrid which isnt technically an "external host"
upvoted 2 times
...
...
devops_devops
1 year, 1 month ago
This question was in exam 15/01/24
upvoted 4 times
...
babakeyfgir
1 year, 1 month ago
It was in EXAM, thanks Examtopic.
upvoted 2 times
...
zellck
2 years ago
1. IP flow verify 2. Connection troubleshoot https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview IP flow verify checks if a packet is allowed or denied to or from a virtual machine. The information consists of direction, protocol, local IP, remote IP, local port, and a remote port. If the packet is denied by a security group, the name of the rule that denied the packet is returned. While any source or destination IP can be chosen, IP flow verify helps administrators quickly diagnose connectivity issues from or to the internet and from or to the on-premises environment.
upvoted 4 times
zellck
2 years ago
https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-connectivity-overview The connection troubleshoot feature of Network Watcher provides the capability to check a direct TCP connection from a virtual machine to a virtual machine (VM), fully qualified domain name (FQDN), URI, or IPv4 address. Network scenarios are complex, they're implemented using network security groups, firewalls, user-defined routes, and resources provided by Azure. Complex configurations make troubleshooting connectivity issues challenging. Network Watcher helps reduce the amount of time to find and detect connectivity issues. The results returned can provide insights into whether a connectivity issue is due to a platform or a user configuration issue. Connectivity can be checked with PowerShell, Azure CLI, and REST API.
upvoted 4 times
...
...
[Removed]
2 years, 1 month ago
Here 1/5/23
upvoted 3 times
...
kf01234
2 years, 4 months ago
A & C (from teacher and slide) Today just finished the total summary of AZ104 extended course (before the exam)
upvoted 1 times
...
favela
2 years, 5 months ago
Correct today came this question and I choose IP flow and troubleshoot passed 900 score
upvoted 3 times
...
EmnCours
2 years, 6 months ago
Box1: IP flow verify Box2: Connection troubleshoot
upvoted 1 times
...
Lazylinux
2 years, 8 months ago
Given Answer is correct IP Flow Verify: This can used to check if packet is allowed or denied to or from a virtual machine. If a packet is being denied by security group, you can see which rule is denying the packet Connection Troubleshoot: Check the connection from a virtual machine to virtual machine, fully qualified domain name, URI or IPv4 address. The test returns similar information returned when using the connection monitor capability, but tests the connection at a point in time, rather than monitoring it over time.
upvoted 2 times
...
ajayasa
2 years, 11 months ago
this question was there on 16/03/2022 with same question and passed with 900 percent
upvoted 1 times
...
ITprof99
3 years, 2 months ago
On exam 01.02.22 Answer: Box 1: IP Flow Verify Box 2: Connection Troubleshoot
upvoted 3 times
...
Tshetu
3 years, 3 months ago
The question came in the exam today 03/12/21.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago