AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Exhibit
{
"type": "Microsoft.Network/networkWatchers/flowLogs",
"apiVersion": "2022-07-01",
"properties": {
"targetResourceId": "/subscriptions/.../microsoft.network/networksecuritygroups/nsg-prod",
"storageId": "/subscriptions/.../storageAccounts/stgflowlog",
"enabled": true,
"retentionPolicy": {
"days": 30,
"enabled": true
},
"format": {
"type": "JSON",
"version": 2
}
}
}Refer to the exhibit. You are deploying NSG flow logs. After deployment, you notice that no logs are being written to the storage account. What is the most likely cause?
⚠ Common exam trap
Many candidates assume the retention policy (0 days) or storage account subscription mismatch is the root cause, but the actual issue is the missing regional Network Watcher dependency, which is a prerequisite for NSG flow logs to function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network Watcher is not enabled in the region.
NSG flow logs require Network Watcher to be enabled in the region where the NSG resides. If Network Watcher is not enabled, the flow logs cannot be written to the storage account because the logging pipeline depends on the Network Watcher agent to capture and forward flow data. Enabling Network Watcher in the region resolves this issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Network Watcher is not enabled in the region.
Why this is correct
NSG flow logs are implemented as a child resource of Network Watcher, so the Network Watcher provider must be registered and the regional Network Watcher instance must exist in the exact Azure region where the NSG resides. Without an active Network Watcher in that region, any attempt to enable flow logs fails with a provisioning error. This is the definitive root cause in this scenario.
- ✗
Retention policy is set to 0 days.
Why it's wrong here
This option is false because the exhibit clearly shows a retention policy of 30 days, not 0. Even if it were 0, that value is valid and means logs would be retained indefinitely, not immediately deleted; it would not prevent flow logs from being created. Since the configured retention is 30 days, this cannot explain the failure.
- ✗
The storage account is in a different subscription.
Why it's wrong here
This is a red herring because Azure supports storing NSG flow logs in a storage account that belongs to a different subscription than the NSG, provided the necessary RBAC permissions are granted to Network Watcher. Cross-subscription storage is a documented and supported configuration, so a subscription mismatch alone does not block flow log creation. Therefore, this option is incorrect.
- ✗
The format version is incorrect.
Why it's wrong here
Format version 2 is the current valid schema for NSG flow logs, including fields like flow state, source and destination IPs, ports, protocol, and TCP flags. A format version error would occur only if the version number were unsupported or malformed, but here it is explicitly set to a supported value. Consequently, the format version is not the cause of the deployment issue.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.