Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

A company is deploying Azure Bastion to provide secure RDP/SSH access to VMs in a virtual network. The security requirement is that all administrative access must be logged and audited. What additional configuration is needed to meet this requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable diagnostic settings on Azure Bastion to send logs to a Log Analytics workspace.

The correct option is B: enabling diagnostic settings on Azure Bastion to send logs to a Log Analytics workspace. Azure Bastion emits session-level audit logs (such as BastionAuditLogs) that record who connected, to which VM, and when; routing these to Log Analytics makes them queryable and auditable, which directly satisfies the logging and auditing requirement. Option A does not fit because NSG flow logs capture network traffic metadata, not the administrative session identity or command context needed for Bastion access auditing. Option C is insufficient because the Azure Activity Log records control-plane operations on the Bastion resource, not the RDP/SSH session activity. Option D is also wrong because diagnostic settings on the target VMs do not capture the Bastion-mediated administrative access events required here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable NSG flow logs on the subnet containing the target VMs.

    Why it's wrong here

    NSG flow logs capture network traffic metadata — source/destination IP, port, protocol, and allow/deny decisions — as packets traverse an NSG. They do not record the Bastion broker's user-authentication payload, the actual Microsoft Entra ID/AD username, or session duration, so they cannot provide the session-level audit details needed for RDP/SSH access review.

  • ✓

    Enable diagnostic settings on Azure Bastion to send logs to a Log Analytics workspace.

    Why this is correct

    Enabling diagnostic settings on the Azure Bastion resource streams the resource-specific category, such as BastionAuditLogs, into a Log Analytics workspace. These logs contain each user connection's source IP, username, target VM, protocol, and session duration, directly satisfying the requirement to audit RDP/SSH sessions through Bastion.

  • ✗

    Enable Azure Activity Log for the Bastion resource.

    Why it's wrong here

    The Azure Activity Log for the Bastion resource is a control-plane/management audit trail showing only admin operations such as creating, updating, or deleting the Bastion host. It contains no records of actual end-user RDP or SSH sessions, source IPs, or the credentials used, so it cannot answer who connected to which VM and for how long.

  • ✗

    Configure diagnostic settings on the target VMs to send logs to Log Analytics.

    Why it's wrong here

    Diagnostic settings on the target VMs forward OS-level logs (e.g., Windows Event Log Security events or Linux Syslog) to Log Analytics. Those logs may show a successful logon event, but because the RDP/SSH connection originates from the Bastion host's private IP, you cannot link the OS event to the original user's source IP or get the session's start/end times as exposed by Bastion.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.