Courseiva
Secure networking →easyMultiple Choice

AZ-500 Secure networking Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "format": "Json",
    "networkWatcherResourceGroupName": "NetworkWatcherRG",
    "storageAccount": {
      "id": "/subscriptions/.../resourceGroups/NetworkWatcherRG/providers/Microsoft.Storage/storageAccounts/flowlogs"
    },
    "enabled": true,
    "retentionPolicy": {
      "days": 30,
      "enabled": true
    },
    "trafficAnalytics": {
      "enabled": true,
      "workspaceId": "/subscriptions/.../resourceGroups/LogAnalytics/providers/Microsoft.OperationalInsights/workspaces/LAWS1"
    }
  }
}
```

You are analyzing network traffic patterns. You have configured NSG flow logs with Traffic Analytics as shown in the exhibit. You need to identify which virtual machines are communicating with a specific malicious IP address. Which tool should you use to query the flow log data?

⚠ Common exam trap

Test-takers frequently confuse NSG flow logs with metrics or topology tools, but only Log Analytics with KQL can perform the ad-hoc, IP-specific queries required to identify malicious communications from the raw flow data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log Analytics workspace using KQL queries

NSG flow logs with Traffic Analytics are stored in a Log Analytics workspace. To query the flow log data and identify which virtual machines are communicating with a specific malicious IP address, you must use Log Analytics with Kusto Query Language (KQL). KQL allows you to filter, aggregate, and join flow log records based on source/destination IP addresses, ports, and protocols, enabling precise identification of affected VMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Storage Explorer

    Why it's wrong here

    Azure Storage Explorer can only browse and download the raw NSG flow log JSON files stored in a storage account. It has no query language or indexing to filter, aggregate, or correlate records across these large files. To find traffic to a specific IP, you would need to manually download and parse hundreds of flow logs, making this approach impractical for any real analysis.

  • ✓

    Log Analytics workspace using KQL queries

    Why this is correct

    Network Watcher Traffic Analytics enriches NSG flow logs and sends them to a Log Analytics workspace, where you can use KQL to investigate traffic. For example, you can query the AzureNetworkAnalytics_CL table, filter by DestinationIP, group by FlowDirection_s, and summarize total bytes or flow counts to identify traffic to a specific IP. KQL supports time-series analysis, joins, and aggregations, making it the correct and efficient tool for this task.

  • ✗

    Azure Monitor Metrics Explorer

    Why it's wrong here

    Azure Monitor Metrics Explorer is designed for numerical time-series metrics, such as CPU utilization or packet counters, not for querying log records. NSG flow logs contain fields like SourceIP, DestinationIP, and Port in textual form, which cannot be parsed or filtered by Metrics Explorer. Even though some network metrics may exist, they lack the per-flow details needed to identify traffic to a given IP.

  • ✗

    Network Watcher Topology

    Why it's wrong here

    Network Watcher Topology renders a static diagram of the network resources in a virtual network, showing relationships such as subnet-to-NSG associations. It does not capture or inspect data-plane traffic, so it cannot reveal which IP addresses are being communicated with or how much traffic flowed to a destination. Topology is a resource relationship visualization, not a traffic analytics tool.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.