Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

A company uses Azure Bastion to provide secure RDP and SSH access to Azure VMs without public IPs. Recently, a security audit recommended logging all connections to Bastion. What should you enable?

⚠ Common exam trap

Test-takers frequently assume NSG flow logs (Option C) capture all network traffic, but Azure Bastion operates at a higher layer and its connection logs are only available through diagnostic settings, not through traditional network-level logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Diagnostic settings on the Bastion resource to stream Bastion logs to a Log Analytics workspace

Azure Bastion does not support Network Security Group flow logs or Azure Activity Logs for capturing connection-level details like source IP, target VM, or session duration. Diagnostic settings on the Bastion resource must be enabled to stream Bastion logs (e.g., BastionAuditLogs) to a Log Analytics workspace, which records all RDP/SSH connection attempts and session metadata. This is the only way to meet the audit requirement for logging all connections to Bastion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Monitor alerts for Bastion resource health

    Why it's wrong here

    Azure Monitor alerts for Bastion resource health monitor the operational status and availability of the Azure Bastion service itself—for example, detecting a degraded backend or outage—rather than auditing who connected via RDP/SSH or when. These alerts fire based on health status changes, not on individual session events. They do not capture the source IP, username, or session duration of connections, so they cannot be used for user access audits.

  • ✗

    Azure Activity Logs for the Bastion resource

    Why it's wrong here

    Azure Activity Logs for the Bastion resource record control-plane operations, such as creating, updating, deleting, or moving the Bastion resource, and administrative actions taken by operators via the Azure portal or APIs. They do not capture data-plane events like an inbound RDP connection through the Bastion service or an SSH session's success/failure. Because Bastion does not log individual user authentication events to the Activity Log, these logs are unsuitable for answering 'who connected and when.'

  • ✗

    Network Security Group flow logs on the subnet containing Bastion

    Why it's wrong here

    Network Security Group flow logs on the Bastion subnet capture network-level traffic data—source and destination IP addresses, ports, and packet/byte counters—for IP flows traversing the subnet. However, they do not contain Bastion-specific semantics: no Bastion session ID, no username or authenticated identity, and no indication of whether an RDP/SSH session was successful or denied. Flow logs are noisy and require additional correlation to map flows to a specific Bastion user, which is often impossible due to Azure's internal NAT and the Bastion service gateway.

  • ✓

    Diagnostic settings on the Bastion resource to stream Bastion logs to a Log Analytics workspace

    Why this is correct

    Diagnostic settings on the Bastion resource are the correct method to collect Azure Bastion's resource logs, specifically the BastionAuditLog, and stream them to a Log Analytics workspace. Once enabled, these logs capture RDP/SSH session events including the source IP address, the target VM, the username, the connection attempt result, and session duration. This data can then be queried with KQL to audit for compliance, investigate unauthorized access, and generate reports on Bastion usage—exactly the requirement in this scenario.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.