mediummultiple choiceObjective-mapped

Exhibit

Storage account: stprod01
Monitoring > Diagnostic settings
Existing settings: none
Metrics: Enabled
Logs: Disabled
Destination: not configured
Requirement: retain operational logs in Log Analytics workspace law-prod

Based on the exhibit, you want the resource logs for the storage account to appear in Log Analytics so you can investigate read and write failures. What should you configure?

Question 1mediummultiple choice
Full question →

Based on the exhibit, you want the resource logs for the storage account to appear in Log Analytics so you can investigate read and write failures. What should you configure?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Create a metric alert rule on the storage account and link it to an action group.

A metric alert can notify operators when a threshold is crossed, but it does not export the underlying resource logs into Log Analytics for investigation.

B

Best answer

Add a diagnostic setting that sends resource logs to the Log Analytics workspace.

Diagnostic settings are the Azure Monitor feature used to route platform logs and metrics from a resource to destinations such as Log Analytics. Because the exhibit shows logs are disabled and no destination is configured, adding a diagnostic setting with the workspace selected is the correct way to make read and write events available for querying.

C

Distractor review

Enable a resource lock so the storage account cannot be modified.

A lock protects the resource from deletion or changes, but it does not collect or export monitoring data. It would not help with log investigation.

D

Distractor review

Move the storage account to a different subscription that already has Log Analytics enabled.

Log Analytics is not inherited by subscription movement in the way this scenario requires. The missing configuration is the diagnostic setting on the storage account itself.

Common exam trap

Common exam trap: NAT rules depend on direction and matching traffic

NAT is not only about the public address. The inside/outside interface roles and the ACL or rule that matches traffic are just as important.

Technical deep dive

How to think about this question

NAT questions usually test address translation, overload/PAT behaviour, static mappings and whether the right traffic is being translated. Read the interface direction and address terms carefully.

KKey Concepts to Remember

  • Static NAT maps one inside address to one outside address.
  • PAT allows many inside hosts to share one public address using ports.
  • Inside local and inside global describe the private and translated addresses.
  • NAT ACLs identify traffic for translation, not always security filtering.

TExam Day Tips

  • Identify inside and outside interfaces first.
  • Check whether the scenario needs static NAT, dynamic NAT or PAT.
  • Do not confuse NAT matching ACLs with normal packet-filtering intent.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

Static NAT maps one inside address to one outside address.

What is the correct answer to this question?

The correct answer is: Add a diagnostic setting that sends resource logs to the Log Analytics workspace. — To investigate read and write failures, the team needs the resource logs in Log Analytics, not just a metric notification. The exhibit shows that metrics are already enabled, but logs are disabled and no destination is configured. A diagnostic setting on the storage account is the feature that exports those logs to the workspace so they can be queried later. Why others are wrong: Metric alerts notify on thresholds but do not provide the detailed logs needed for investigation. A lock only restricts changes and has nothing to do with telemetry. Moving the storage account is irrelevant because log export is configured per resource through diagnostic settings.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.