Your on-premises network is connected to VNet1 by a site-to-site VPN. Traffic from Server1 to VM1 is failing to reach VM1. To inspect the contents of the traffic sent from Server1 to VM1, what should you do first?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable NSG flow logs on NSG1..
Why this is the answer
Enabling NSG flow logs on NSG1 is the correct first step because NSG flow logs record information about IP traffic flowing through an NSG. This will show if the traffic from Server1 is even reaching NSG1 and, if so, whether it's being allowed or denied by any NSG rules. This provides crucial network-level visibility for troubleshooting connectivity issues to Azure VMs. Enabling Windows Firewall logging on Server1 would only show traffic leaving Server1, not what happens to it once it enters the Azure network. Enabling the Packet Monitoring extension from Windows Admin Center is a good tool for detailed packet analysis on a specific server but doesn't provide the network-wide visibility needed to see if traffic is being blocked by an NSG. Creating a packet capture in Azure Network Watcher is a more advanced step for detailed packet analysis after you've determined that traffic is indeed reaching the Azure network and potentially being dropped at a specific point; it's not the first step for general connectivity troubleshooting.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed