AZ-700 exam dumps

AZ-700 practice question 271 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 271

Select 2

You are the network engineer for a company that has deployed a Windows Server virtual machine (VM) in Azure. The VM is protected by a Network Security Group (NSG) on its subnet that explicitly allows inbound RDP from 203.0.113.0/24 and denies all other inbound RDP traffic. A developer from the IP address range 198.51.100.0/24 claims they are still able to establish an RDP connection to the VM. You need to confirm whether traffic from this address range is indeed being blocked by the NSG. Which two methods can you use to validate the NSG flow rules and confirm the actual behavior?

  1. A

    Use Azure Network Watcher IP Flow Verify to test traffic from the developer� IP address to the VM� IP and RDP port.

  2. B

    Check the Windows Server Event Viewer for security logs and application logs on the VM.

  3. C

    Use Azure Network Watcher Connection Monitor to continuously track connectivity status from the developer� IP address to the subnet.

  4. D

    Configure an Azure Monitor metric alert on RDP port usage to identify blocked traffic from 198.51.100.0/24.

  5. E

    Enable NSG Flow Logs in Azure Network Watcher and analyze the logs to see whether traffic from 198.51.100.0/24 is blocked.

Show answer and explanation

Correct answers: A, E

Explanation

To validate NSG flow rules effectively, you can utilize IP Flow Verify in Azure Network Watcher for quick, on-demand checks of allow/deny outcomes based on source, destination, and port. Additionally, enabling and reviewing NSG Flow Logs provides historical evidence of which connections were permitted or blocked. For more details, refer to Microsoft� documentation on Network Watcher IP Flow Verify (https://learn.microsoft.com/azure/network-watcher/network-watcher-ip-flow-verify-overview) and NSG Flow Logs (https://learn.microsoft.com/azure/network-watcher/network-security-group-flow-logging-overview).

  • A. Correct.

    Option 1 is correct. Using Azure Network Watcher� IP Flow Verify, you can specify the source IP (from 198.51.100.0/24), destination IP (the VM), and the RDP port (3389) to check if traffic is allowed or denied by NSG rules. This provides an immediate, rule-based verdict on whether traffic is permitted or blocked.

  • B. Incorrect.

    Option 2 is incorrect. While Windows Event Viewer logs can show local system and security events, they do not reliably indicate whether traffic is blocked at the NSG level in Azure. NSG validation requires Azure-level diagnostics for complete visibility.

  • C. Incorrect.

    Option 3 is incorrect. Connection Monitor can help monitor end-to-end connectivity, but it does not directly confirm if a specific NSG rule is blocking the traffic. You also need an agent-enabled endpoint or a validated test scenario. IP Flow Verify is more direct for pinpointing NSG rule actions.

  • D. Incorrect.

    Option 4 is incorrect. Metric alerts in Azure Monitor for port usage can track overall usage but do not directly confirm NSG block or allow rules at the network perimeter. It would show metrics but not the enforcement status due to specific addresses being blocked.

  • E. Correct.

    Option 5 is correct. NSG Flow Logs provide a record of actual traffic flows and whether the traffic is allowed or denied. By enabling and analyzing these logs, you can see whether traffic from the 198.51.100.0/24 range is indeed blocked as intended.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam