AZ-700 exam dumps

AZ-700 practice question 268 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 268

Single answer

You manage a mission-critical web application running on multiple Azure VMs behind Network Security Groups (NSGs). Recently, your security team noticed suspicious outbound connections from the front-end VM to an external IP address. You decide to review NSG flow logs in Network Watcher to determine whether the traffic was allowed or denied and to identify the source and destination IP addresses. Which approach will most accurately help you interpret the traffic details in the flow logs?

  1. A

    Focus on the 'flowState', 'sourceIP', 'destinationIP', 'destinationPort', 'direction', and 'action' fields in the flow logs to confirm if traffic was allowed or blocked.

  2. B

    Rely solely on the 'bytesTransmitted' field to identify any unusual inbound traffic from the suspicious IP address.

  3. C

    Use NSG flow logs to retrieve application-level data, such as HTTP request headers and payload details, for real-time threat analysis.

  4. D

    Extract flow data directly from the Azure Monitor activity logs only, as that automatically includes all inbound and outbound flow details in real time.

Show answer and explanation

Correct answer: A

Explanation

To effectively troubleshoot and analyze NSG flow logs, review the standard fields that include source/destination IP, port, direction, and action. This data helps you pinpoint whether the traffic was legitimate or suspicious. For more information, refer to the Azure Network Watcher documentation (https://learn.microsoft.com/azure/network-watcher/network-watcher-nsg-flow-logging-overview) which outlines how to enable and interpret NSG flow logs for network monitoring and security investigations.

  • A. Correct.

    Option 1 is correct because NSG flow logs provide insights into traffic based on key fields�flowState (the flow action's state), sourceIP, destinationIP, destinationPort, direction (inbound or outbound), and action (allow or deny). These fields are critical for determining whether traffic was permitted or blocked and for capturing essential details of the connection. This aligns with Microsoft best practices for interpreting flow logs, helping you spot suspicious traffic patterns.

  • B. Incorrect.

    Option 2 is incorrect because focusing solely on 'bytesTransmitted' does not provide enough information about direction, ports, or whether traffic was allowed or denied. Although the volume of transmitted data may flag potential anomalies, it does not alone confirm the nature or legitimacy of the traffic.

  • C. Incorrect.

    Option 3 is incorrect because NSG flow logs operate at the network level and do not capture application-layer data like request headers or payloads. They do not provide deep packet inspection to reveal protocols higher than Layer 4 (transport layer).

  • D. Incorrect.

    Option 4 is incorrect because while Azure Monitor can provide various insights and integrations, flow logs are specific to Network Watcher� NSG flow log feature. You should configure NSG flow logging and log analytics to correlate or analyze the data, rather than relying solely on the default activity logs.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam