AZ-500 Secure networking Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"format": "Json",
"networkWatcherResourceGroupName": "NetworkWatcherRG",
"storageAccount": {
"id": "/subscriptions/.../resourceGroups/NetworkWatcherRG/providers/Microsoft.Storage/storageAccounts/flowlogs"
},
"enabled": true,
"retentionPolicy": {
"days": 30,
"enabled": true
},
"trafficAnalytics": {
"enabled": true,
"workspaceId": "/subscriptions/.../resourceGroups/LogAnalytics/providers/Microsoft.OperationalInsights/workspaces/LAWS1"
}
}
}
```You are analyzing network traffic patterns. You have configured NSG flow logs with Traffic Analytics as shown in the exhibit. You need to identify which virtual machines are communicating with a specific malicious IP address. Which tool should you use to query the flow log data?
⚠ Common exam trap
Test-takers frequently confuse NSG flow logs with metrics or topology tools, but only Log Analytics with KQL can perform the ad-hoc, IP-specific queries required to identify malicious communications from the raw flow data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log Analytics workspace using KQL queries
NSG flow logs with Traffic Analytics are stored in a Log Analytics workspace. To query the flow log data and identify which virtual machines are communicating with a specific malicious IP address, you must use Log Analytics with Kusto Query Language (KQL). KQL allows you to filter, aggregate, and join flow log records based on source/destination IP addresses, ports, and protocols, enabling precise identification of affected VMs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Storage Explorer
Why it's wrong here
Azure Storage Explorer can only browse and download the raw NSG flow log JSON files stored in a storage account. It has no query language or indexing to filter, aggregate, or correlate records across these large files. To find traffic to a specific IP, you would need to manually download and parse hundreds of flow logs, making this approach impractical for any real analysis.
- ✓
Log Analytics workspace using KQL queries
Why this is correct
Network Watcher Traffic Analytics enriches NSG flow logs and sends them to a Log Analytics workspace, where you can use KQL to investigate traffic. For example, you can query the AzureNetworkAnalytics_CL table, filter by DestinationIP, group by FlowDirection_s, and summarize total bytes or flow counts to identify traffic to a specific IP. KQL supports time-series analysis, joins, and aggregations, making it the correct and efficient tool for this task.
- ✗
Azure Monitor Metrics Explorer
Why it's wrong here
Azure Monitor Metrics Explorer is designed for numerical time-series metrics, such as CPU utilization or packet counters, not for querying log records. NSG flow logs contain fields like SourceIP, DestinationIP, and Port in textual form, which cannot be parsed or filtered by Metrics Explorer. Even though some network metrics may exist, they lack the per-flow details needed to identify traffic to a given IP.
- ✗
Network Watcher Topology
Why it's wrong here
Network Watcher Topology renders a static diagram of the network resources in a virtual network, showing relationships such as subnet-to-NSG associations. It does not capture or inspect data-plane traffic, so it cannot reveal which IP addresses are being communicated with or how much traffic flowed to a destination. Topology is a resource relationship visualization, not a traffic analytics tool.
Visual reference
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.