Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AZ-103 topic 4 question 59 discussion

Actual exam question from Microsoft's AZ-103
Question #: 59
Topic #: 4
[All AZ-103 Questions]

HOTSPOT -
You have an Azure virtual network named VNet1 that connects to your on-premises network by using a site-to-site VPN. VNet1 contains one subnet named
Subnet1.
Subnet1 is associated to a network security group (NSG) named NSG1. Subnet1 contains a basic internal load balancer named ILB1. ILB1 has three Azure virtual machines in the backend pool.
You need to collect data about the IP addresses that connects to ILB1. You must be able to run interactive queries from the Azure portal against the collected data.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: An Azure Log Analytics workspace
In the Azure portal you can set up a Log Analytics workspace, which is a unique Log Analytics environment with its own data repository, data sources, and solutions

Box 2: ILB1 -
Reference:
https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-quick-create-workspace https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-standard-diagnostics
Configure and manage virtual networks

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Robinsonasir
Highly Voted 4 years ago
I think it is NSG . basic internal load balancer doesn't have Metrics enabled .it need to be standard LB
upvoted 11 times
...
sellamibassem
Highly Voted 4 years ago
I think that first answer is "An azure storage account" and second answer is "NSG1" https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-portal?toc=/azure/virtual-network/toc.json
upvoted 8 times
arcanjo
3 years, 11 months ago
sellamibassen, the question ask to "You must be able to run interactive queries from the Azure portal against the collected data". Using an storage account, you need to download the log file to analyze.
upvoted 4 times
...
I
3 years, 2 months ago
Strongly agree.
upvoted 1 times
...
...
mikewallace8372
Most Recent 3 years, 3 months ago
2nd. NSG for me
upvoted 1 times
...
ujj
3 years, 3 months ago
Refer this -https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-nsg-manage-log#:~:text=View%20and%20analyze%20logs,-To%20learn%20how&text=Azure%20Monitor%20logs%3A%20You%20can,interface%20in%20a%20virtual%20machine. Basic ILB can not send logs to azure monitor but , NSG can collect all the accepted/denied flow logs to log analytics for interactive queries . so correct answer 1. Log Analytics 2. NSG
upvoted 3 times
...
revyek10
3 years, 5 months ago
2 nd one should be Azure VM's. From ILB the connections will go to background VW's, if we enable diagnostics on background Azure VM's. We can get the dat about the IP addresses connected to it. 1) Log Analytics Workspace (as we can run interactive quarries) 2) VM's in the backend pool
upvoted 1 times
...
Thi
3 years, 5 months ago
1 option same as answer 2nd option for me NSG1
upvoted 1 times
...
Chris78
3 years, 6 months ago
the second part is NSG https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-nsg-manage-log
upvoted 2 times
...
ABDE
3 years, 7 months ago
Azure virtual networks have NSG flow logs, which provide you information about ingress and egress IP traffic through a Network Security Group associated to individual network interfaces, VMs, or subnets. 2. It might be NSG
upvoted 2 times
...
Loma
3 years, 8 months ago
Tested in Azure, confirm that Analytics Logs is only available in PUBLIC BASIC LB. INTERNAL BASIC LB could not be configured to send events to Logs Analytic space. Answer should be NSG.
upvoted 2 times
...
Ralgh
3 years, 8 months ago
Think 2nds one should be NSG as this can use the MAC addresses of incoming connections to the 3 VMs in this case
upvoted 2 times
...
BlackHole
3 years, 9 months ago
Here they gave, in second box, NSG1 as correct answer: https://www.examtopics.com/exams/microsoft/az-102/view/13/
upvoted 6 times
...
Hanuman
3 years, 10 months ago
Correct answer should be: 1. Log analytics workspace. 2. NSG1
upvoted 3 times
...
Kiwino
3 years, 10 months ago
Box1: An Azure Log Analytics Workspace Box2: NSG1 (as basic internal Load Balancer can’t have diagnostics option)
upvoted 4 times
...
gerardR
3 years, 11 months ago
After check that with internal LB the Diagnostic Settings are not available (just in a external/public one) I would say that the provided solution seems correct.
upvoted 1 times
...
LowerSouth
3 years, 11 months ago
Log Analytics workspace on NSG1 Log Analytics rather than Storage account for the interactive queries NSG1 because basic Internal load balancers (pubic lb is a different story) do not have logging settings
upvoted 5 times
ExamGuy01
3 years, 11 months ago
You can't configure SA on a NSG log! https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-azure-resource-manager so the question remains, basic LB and ip filtering or NSG flow logs
upvoted 1 times
...
...
CristianN
3 years, 11 months ago
Azure storage account is needed for archiving.
upvoted 1 times
...
asdfgh1234567
3 years, 11 months ago
Guys this should be NSG Flow Logs and stored in a Storage Account. https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview The Basic LB will not provide logging for IP flow which is what the question is asking. The Basic LB can provide logs, but these are administrative and activity logs, not IP/traffic logs. One thing to bear in mind with Flow Logs on an NSG with VMs behind a Basic Load Balancer: VMs that don't have a public IP address assigned via a public IP address associated with the NIC as an instance-level public IP, or that are part of a basic load balancer back-end pool, use default SNAT and have an IP address assigned by Azure to facilitate outbound connectivity. As a result, you might see flow log entries for flows from internet IP addresses, if the flow is destined to a port in the range of ports assigned for SNAT. While Azure won't allow these flows to the VM, the attempt is logged and appears in Network Watcher's NSG flow log by design. We recommend that unwanted inbound internet traffic be explicitly blocked with NSG.
upvoted 1 times
arcanjo
3 years, 11 months ago
The question ask to "You must be able to run interactive queries from the Azure portal against the collected data". Using an storage account, you need to download the log file to analyze.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...