VM3 fails to meet the technical requirements. To determine whether network security groups are causing the issue, which tool should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: IP flow verify in Azure Network Watcher.
Why this is the answer
IP flow verify in Azure Network Watcher is the correct tool because it allows you to check if a packet is allowed or denied to or from a virtual machine, and it specifies which Network Security Group (NSG) rule is responsible. This directly helps determine if NSGs are blocking network traffic to VM3. Diagram in VNet1 is incorrect as it only shows the network topology, not the real-time flow or NSG rule impact. Diagnostic settings in Azure Monitor are for collecting logs and metrics, not for real-time NSG rule validation. Diagnose and solve problems in Traffic Manager profiles is irrelevant as Traffic Manager deals with global traffic distribution, not VM-level network connectivity issues caused by NSGs. The security recommendations in Azure Advisor provide general security best practices, not specific troubleshooting for network flow issues.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed