An application server (app-db-01) cannot reach an external analytics service on TCP 9000. The team suspects an NSG rule is blocking outbound traffic but there are multiple NSGs (subnet and NIC level) and Azure Firewall in the path. Which Network Watcher artifact will show the aggregated effective security rules and let you identify which specific rule (name and priority) is blocking that traffic for the NIC?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Network Watcher IP Flow Verify for the specific 5-tuple (source IP, dest IP, protocol TCP and port 9000); IP Flow Verify will report whether the flow is allowed or denied and the exact NSG rule (name and priority) that matched..
Why this is the answer
Network Watcher's IP Flow Verify is designed precisely for this scenario. By specifying the 5-tuple (source IP, destination IP, protocol, source port, and destination port), it simulates the traffic flow and reports whether it's allowed or denied. Crucially, it identifies the specific NSG rule (name and priority) that permitted or denied the flow, even across multiple NSGs. Azure Firewall diagnostic logs would show firewall rules, not NSG rules, and Azure Firewall does not enforce NSG rules on behalf of the VM; NSGs are applied separately. The Effective Routes blade shows routing, not security rules. NSG Flow Logs record traffic that has already occurred and can take time to process, making them less suitable for immediate troubleshooting of a blocking rule.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed