AZ-700 exam dumps

AZ-700 practice question 265 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 265

Select 2

You are managing an Azure environment that includes multiple NSGs attached to critical virtual machines. The security team requires detailed insights into network traffic to identify potential anomalies. They ask you to enable NSG flow logs and store the logs in an existing Log Analytics workspace for real-time analytics and simplified querying. Which two of the following steps must you perform to correctly implement NSG flow logs in this scenario?

  1. A

    A. Enable NSG flow logs via Azure Network Watcher, select Version 2, and choose the existing Log Analytics workspace as the destination.

  2. B

    B. Create a new Event Hub and set the NSG flow logs to stream directly into the Event Hub for analysis.

  3. C

    C. Configure Traffic Analytics, if needed, by enabling 'Traffic Analytics' under the NSG flow logs settings and specifying the same Log Analytics workspace.

  4. D

    D. Modify each NSG� diagnostic settings to send metric data to the Log Analytics workspace under the 'Metrics' section.

  5. E

    E. Enable flow logs at the subscription level by turning on 'Flow Logs Global' under the subscription� diagnostic settings.

Show answer and explanation

Correct answers: A, C

Explanation

To implement NSG flow logs for advanced insights, you enable flow logs per NSG through Azure Network Watcher. If you select Version 2, you can integrate Traffic Analytics and select a Log Analytics workspace for simplified querying and real-time analysis. The key references are from Microsoft� documentation on NSG flow logs in Network Watcher and Traffic Analytics (https://docs.microsoft.com/azure/network-watcher/network-watcher-nsg-flow-logging-overview). Configuring diagnostic metrics alone or relying on subscription-level diagnostics does not fulfill the requirement for storing and analyzing detailed NSG flow data.

  • A. Correct.

    Option A is correct. To implement NSG flow logs for analytics in Log Analytics, you typically enable flow logs under Network Watcher, select the NSG(s), choose flow logs Version 2 for advanced capabilities, and then select the existing Log Analytics workspace as the destination.

  • B. Incorrect.

    Option B is incorrect. While you can send flow logs to an Event Hub, the scenario specifically requires storing logs in Log Analytics for near real-time queries. Using an Event Hub might be useful for external processing, but it does not satisfy the requirement to store logs in an existing Log Analytics workspace for immediate analysis.

  • C. Correct.

    Option C is correct. Traffic Analytics is an additional feature that can be enabled under flow logs to provide aggregated insights and visualizations. You must specify the same Log Analytics workspace if you want analytics and flow logs data in the same place.

  • D. Incorrect.

    Option D is incorrect. Simply sending diagnostic metrics to a Log Analytics workspace under the 'Metrics' section does not generate flow logs. NSG flow logs must be turned on via Network Watcher� flow logs settings, which is separate from standard diagnostic metrics.

  • E. Incorrect.

    Option E is incorrect. There is no 'Flow Logs Global' setting at the subscription level. Flow logs are enabled on a per-NSG basis within Network Watcher. Subscription-level diagnostic settings do not replace the need to enable flow logs at the NSG level.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam