Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

A company uses Azure Firewall to inspect traffic between a spoke VNet hosting a web application and a hub VNet hosting a SQL database. The web application fails to connect to the database after a recent network topology change. You verify that the Azure Firewall rules allow the traffic. Which Azure Network Watcher feature should you use to identify the root cause?

⚠ Common exam trap

The trap is that IP flow verify is mistakenly thought to evaluate Azure Firewall and route tables, but it only evaluates effective NSGs on a single interface. Connection troubleshoot is the appropriate tool for diagnosing end-to-end connectivity issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connection troubleshoot

Connection troubleshoot (Option A) is the correct choice because it performs an end-to-end connectivity test from the source VM to the destination, evaluating the actual path, including Azure Firewall rules, NSGs, and route tables. Since the firewall rules are confirmed to allow the traffic, Connection troubleshoot can identify if a UDR misrouting or an NSG on the source or destination subnet is blocking the connection. IP flow verify only checks NSG rules at a single network interface and does not evaluate route tables or the entire path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Connection troubleshoot

    Why this is correct

    Connection troubleshoot in Azure Network Watcher performs an end-to-end connectivity test between a source and destination, checking reachability over the network path. However, it returns a pass/fail status and may only indicate the hop where connectivity fails, not the specific security rule (such as an Azure Firewall rule or NSG rule) that dropped the packet. This makes it less precise than IP flow verify for identifying exactly which deny rule caused the blocking.

  • ✗

    Next hop

    Why it's wrong here

    Next hop diagnostics in Network Watcher determines the route and next hop IP address for traffic sent from a VM to a given destination. It only reveals the routing path (e.g., to Azure Firewall or a virtual appliance) and does not evaluate whether any security rules along that path allow or deny the packet. Even if the next hop is correctly set to Azure Firewall, the firewall may still drop the traffic, so this tool cannot confirm the specific firewall rule that blocked it.

  • ✗

    Network Performance Monitor

    Why it's wrong here

    Network Performance Monitor is a Network Watcher-based monitoring solution designed to measure latency, packet loss, and network availability between endpoints using monitoring agents. It provides aggregate performance metrics and alerts but does not simulate individual packets through security rule evaluation. As a result, it cannot determine whether Azure Firewall is denying a particular traffic flow or identify the specific rule responsible for the drop.

  • ✗

    IP flow verify

    Why it's wrong here

    IP flow verify in Azure Network Watcher is the correct tool because it simulates a packet with the exact source IP, destination IP, protocol, and port, then evaluates it against all effective security rules, including Azure Firewall rules and NSG rules. It returns a definitive 'Allowed' or 'Denied' result and lists the specific rule that caused the decision, enabling precise identification of the firewall rule blocking traffic. This targeted diagnostic makes it superior to the other options for troubleshooting a suspected Azure Firewall deny.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.