You have 10 virtual machines on a single subnet protected by one network security group (NSG). You need to log the network traffic to an Azure Storage account. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable NSG flow logs..
Why this is the answer
Enabling NSG flow logs is the correct solution because NSG flow logs capture information about IP traffic flowing through an NSG. This data includes source and destination IP addresses, ports, protocols, and whether the traffic was allowed or denied, and can be sent directly to an Azure Storage account for analysis. Installing the Network Performance Monitor solution is incorrect as it focuses on network connectivity and performance issues, not detailed traffic flow logging for NSGs. Creating an Azure Log Analytics workspace is a destination for logs but doesn't, by itself, initiate the logging of NSG traffic. Enabling diagnostic logging for the NSG captures operational logs about the NSG itself (e.g., configuration changes), not the actual network traffic flowing through it.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed