Fabrikam runs a multi-tier app in vnet-prod with a route table rtb-azure routing 0.0.0.0/0 to a virtual appliance at 10.0.100.4. A backend VM (dbvm01) in subnet db-subnet cannot reach an external API at 52.160.0.8 — traffic appears to be dropped (black hole). Which Network Watcher action should you run to identify the router/next hop being chosen for traffic from dbvm01 to 52.160.0.8 and detect if the packet is being sent to an unexpected next hop (black hole)?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Network Watcher Next Hop for the VM's NIC (or specify the VM IP) with destination 52.160.0.8; the result reports the computed next hop type and next hop IP, revealing if a virtual appliance, Internet, None (black hole), or VNetLocal is selected..
Why this is the answer
Network Watcher Next Hop is the precise tool for this scenario because it directly reports the next hop type and IP address for a specified source (VM NIC/IP) and destination. This allows you to confirm if the traffic is being routed to the expected virtual appliance (10.0.100.4) or if it's being black-holed (Next Hop type 'None') or routed elsewhere. IP Flow Verify checks NSG rules, not routing. NSG flow logs show allowed/denied traffic by NSGs, not the next hop. Packet capture observes actual traffic but doesn't directly compute the next hop chosen by Azure's routing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed