AZ-500 Secure networking Practice Question
Which TWO actions can be taken using Azure Network Watcher?
⚠ Common exam trap
Many exam-takers confuse Network Watcher's diagnostic tools (IP flow verify, next hop) with configuration services (Private Link, WAF, Azure Firewall), which are separate Azure resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Diagnose whether a security rule is blocking traffic to a VM.
Azure Network Watcher includes the IP flow verify capability, which checks whether a packet is allowed or denied to or from a VM and identifies the specific security rule (NSG rule) responsible, so option A is correct. It also includes the Next hop capability, which determines the next hop type and IP address for traffic originating from a VM, validating routing behavior, so option D is correct. Options B, C, and E are incorrect because private endpoints, Application Gateway WAF policies, and Azure Firewall rules are configured through their respective services (Private Link, Application Gateway, and Azure Firewall), not through Network Watcher.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Diagnose whether a security rule is blocking traffic to a VM.
Why this is correct
Network Watcher's IP flow verify checks whether a packet is allowed or denied by a network security group (NSG) based on the selected VM, network interface, and security rules. You provide source and destination IPs, port, protocol, and direction, and it returns the specific NSG rule that permitted or blocked the traffic. This directly answers whether a security rule is blocking traffic to a VM, making it a core diagnostic feature.
- ✗
Create and manage private endpoints.
Why it's wrong here
Creating and managing private endpoints is a function of Azure Private Link, not Azure Network Watcher. Private endpoints are network resources that provide private connectivity to PaaS services, and they are configured via the Private Link Center or the resource's networking settings. Network Watcher is a monitoring and diagnostic tool and does not provision or manage connectivity endpoints.
- ✗
Configure WAF policies on Application Gateway.
Why it's wrong here
WAF policies for Application Gateway are managed through Application Gateway's Web Application Firewall configuration, Azure Firewall Manager, or a dedicated WAF policy resource. Network Watcher does not have any capability to author or modify WAF policies; its scope is network-level monitoring and diagnostics, such as flow logs and packet capture. Therefore, configuring a WAF policy is outside Network Watcher's responsibilities.
- ✓
Determine the next hop for traffic from a VM.
Why this is correct
The Next Hop diagnostic in Network Watcher identifies the next hop type and IP address for traffic sent from a specific VM's network interface to a destination IP. It effectively shows whether the traffic routes to the internet, a virtual network gateway, a virtual appliance, or the virtual network itself, based on effective routes. This makes it the correct tool for determining the routing path of traffic from a VM.
- ✗
Configure Azure Firewall rules.
Why it's wrong here
Azure Firewall rules are defined in Azure Firewall policy and applied through Azure Firewall Manager, not through Network Watcher. Network Watcher can be used to capture traffic logs or configure diagnostic settings to monitor Azure Firewall activity, but it cannot create, edit, or delete firewall rules. Thus, this action falls under firewall management rather than network diagnostics.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.