NSG1 is associated to the NIC of VM1 and contains the rules shown. You collected NSG flow logs for five minutes capturing these activities: two RDP sessions originating from VM1 to VM2 (each from a different TCP source port), and three SSH sessions originating from VM2 to VM1 (each from a different TCP source port). When Traffic Analytics aggregates the flows from these events, how many aggregated flow entries will it report?
Choose an answer
Tap an option to check your answer.
Correct answer: 5.
Why this is the answer
Traffic Analytics aggregates flows based on a 5-tuple (source IP, destination IP, source port, destination port, protocol). Each unique 5-tuple constitutes a distinct flow. In this scenario: 1. Two RDP sessions from VM1 to VM2: Each RDP session originates from a different TCP source port on VM1 but targets the same destination IP (VM2's IP), destination port (3389), and protocol (TCP). This results in two distinct 5-tuples, hence two aggregated flow entries. 2. Three SSH sessions from VM2 to VM1: Each SSH session originates from a different TCP source port on VM2 but targets the same destination IP (VM1's IP), destination port (22), and protocol (TCP). This results in three distinct 5-tuples, hence three aggregated flow entries. Therefore, the total number of aggregated flow entries will be 2 (for RDP) + 3 (for SSH) = 5.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed