Courseiva
Secure networking →easyMultiple Select

AZ-500 Secure networking Practice Question

Which TWO actions can be taken using Azure Network Watcher?

⚠ Common exam trap

Many exam-takers confuse Network Watcher's diagnostic tools (IP flow verify, next hop) with configuration services (Private Link, WAF, Azure Firewall), which are separate Azure resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Diagnose whether a security rule is blocking traffic to a VM.

Azure Network Watcher includes the IP flow verify capability, which checks whether a packet is allowed or denied to or from a VM and identifies the specific security rule (NSG rule) responsible, so option A is correct. It also includes the Next hop capability, which determines the next hop type and IP address for traffic originating from a VM, validating routing behavior, so option D is correct. Options B, C, and E are incorrect because private endpoints, Application Gateway WAF policies, and Azure Firewall rules are configured through their respective services (Private Link, Application Gateway, and Azure Firewall), not through Network Watcher.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Diagnose whether a security rule is blocking traffic to a VM.

    Why this is correct

    Network Watcher's IP flow verify checks whether a packet is allowed or denied by a network security group (NSG) based on the selected VM, network interface, and security rules. You provide source and destination IPs, port, protocol, and direction, and it returns the specific NSG rule that permitted or blocked the traffic. This directly answers whether a security rule is blocking traffic to a VM, making it a core diagnostic feature.

  • ✗

    Create and manage private endpoints.

    Why it's wrong here

    Creating and managing private endpoints is a function of Azure Private Link, not Azure Network Watcher. Private endpoints are network resources that provide private connectivity to PaaS services, and they are configured via the Private Link Center or the resource's networking settings. Network Watcher is a monitoring and diagnostic tool and does not provision or manage connectivity endpoints.

  • ✗

    Configure WAF policies on Application Gateway.

    Why it's wrong here

    WAF policies for Application Gateway are managed through Application Gateway's Web Application Firewall configuration, Azure Firewall Manager, or a dedicated WAF policy resource. Network Watcher does not have any capability to author or modify WAF policies; its scope is network-level monitoring and diagnostics, such as flow logs and packet capture. Therefore, configuring a WAF policy is outside Network Watcher's responsibilities.

  • ✓

    Determine the next hop for traffic from a VM.

    Why this is correct

    The Next Hop diagnostic in Network Watcher identifies the next hop type and IP address for traffic sent from a specific VM's network interface to a destination IP. It effectively shows whether the traffic routes to the internet, a virtual network gateway, a virtual appliance, or the virtual network itself, based on effective routes. This makes it the correct tool for determining the routing path of traffic from a VM.

  • ✗

    Configure Azure Firewall rules.

    Why it's wrong here

    Azure Firewall rules are defined in Azure Firewall policy and applied through Azure Firewall Manager, not through Network Watcher. Network Watcher can be used to capture traffic logs or configure diagnostic settings to monitor Azure Firewall activity, but it cannot create, edit, or delete firewall rules. Thus, this action falls under firewall management rather than network diagnostics.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.