AZ-500 exam dumps

AZ-500 practice question 72 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 72

Select 3

Your company hosts a web application in a virtual network along with multiple backend services. Recently, you've noticed an unusual spike in inbound traffic, and you suspect that certain IP addresses might be probing your infrastructure for vulnerabilities. You plan to use Azure Network Watcher to identify and analyze suspicious network activity. Which two actions can help you detect and investigate malicious traffic using Network Watcher?

  1. A

    Enable NSG Flow Logs for your Network Security Groups and analyze them using Traffic Analytics

  2. B

    Configure the Azure Network Watcher Agent extension on each VM to automatically block all suspicious IP addresses

  3. C

    Use IP Flow Verify to check if traffic from specific IP addresses is being allowed or denied

  4. D

    Enable Azure Firewall threat intelligence filtering directly from Network Watcher

  5. E

    Use the Packet capture feature to gather real-time packet-level data for deeper analysis

Show answer and explanation

Correct answers: A, C, E

Explanation

To monitor and investigate suspicious network activity using Azure Network Watcher, you can combine NSG Flow Logs, IP Flow Verify, and Packet capture to gain both high-level and granular visibility into your traffic. NSG Flow Logs and Traffic Analytics provide insight into overall trends and potential malicious patterns, while IP Flow Verify pinpoints whether specific IP addresses or ports are permitted or blocked. Packet capture enables more detailed, real-time analysis of traffic and payloads. For more details, refer to Microsoft’s official documentation on Network Watcher: https://learn.microsoft.com/azure/network-watcher.

  • A. Correct.

    Correct. Enabling NSG Flow Logs allows you to capture information about ingress and egress IP traffic through your Network Security Groups. You can store the logs in a storage account or send them to a Log Analytics workspace. Traffic Analytics can then be used to derive insights such as inbound and outbound traffic patterns and possible malicious connections.

  • B. Incorrect.

    Incorrect. The Azure Network Watcher Agent extension is used for specific diagnostic scenarios such as connection troubleshooting and packet capture, but it does not automatically block suspicious IP addresses. Blocking traffic is handled through Network Security Groups or other firewall solutions.

  • C. Correct.

    Correct. IP Flow Verify helps you test whether traffic is allowed or denied by NSG rules for a given source and destination. If you're seeing unexpected inbound connections, you can use this tool to verify whether certain IP addresses are indeed being permitted or blocked by your NSGs.

  • D. Incorrect.

    Incorrect. Azure Firewall threat intelligence filtering is a separate service and is not enabled directly within Network Watcher. While integrating Azure Firewall can enhance your overall network security, this option doesn't describe a feature provided by Network Watcher itself.

  • E. Correct.

    Correct. Packet capture in Network Watcher allows you to gather detailed network traffic information at the packet level. This feature is especially useful when investigating suspicious activity because you can analyze the actual data payloads and header information for signs of malicious behavior.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam