Wingtip Toys wants to enable NSG flow logs for all subnets and keep logs for 365 days in the most cost-effective way while retaining query capability for troubleshooting. Which configuration meets the requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable NSG flow logs (Network Watcher) and send them to a Storage Account with a lifecycle management policy to retain blobs for 365 days (move to cooler tiers or delete after 365 days); for ad-hoc queries, periodically export necessary subsets to a Log Analytics workspace..
Why this is the answer
The most cost-effective solution for long-term storage and query capability is to send NSG flow logs to an Azure Storage Account. Storage Accounts offer tiered storage (hot, cool, archive) and lifecycle management policies, allowing cost optimization by moving older data to cooler tiers. This meets the 365-day retention requirement efficiently. For ad-hoc querying, exporting specific subsets to a Log Analytics workspace provides powerful analytics without incurring the higher cost of sending all logs to Log Analytics for the entire retention period. Sending logs only to a Log Analytics workspace for 365 days would be significantly more expensive due to Log Analytics pricing for ingestion and retention. Event Hubs is a streaming service, not designed for long-term, cost-effective storage and direct querying of historical data. Storing logs on VM local disks is not a scalable, reliable, or secure solution for NSG flow logs, which are generated by the network infrastructure, not individual VMs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed