Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AZ-104 topic 2 question 35 discussion

Actual exam question from Microsoft's AZ-104
Question #: 35
Topic #: 2
[All AZ-104 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You need to ensure that an Azure Active Directory (Azure AD) user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.
Solution: You assign the Reader role at the subscription level to Admin1.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Your account must meet one of the following to enable traffic analytics:
Your account must have any one of the following Azure roles at the subscription scope: owner, contributor, reader, or network contributor.
Reference:
https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
asmodeus
Highly Voted 3 years, 4 months ago
Traffic Analytics requires the following prerequisites: A Network Watcher enabled subscription. Network Security Group (NSG) flow logs enabled for the NSGs you want to monitor. An Azure Storage account, to store raw flow logs. An Azure Log Analytics workspace, with read and write access. Your account must meet one of the following to enable traffic analytics: Your account must have any one of the following Azure roles at the subscription scope: owner, contributor, reader, or network contributor.
upvoted 97 times
visave
3 years, 4 months ago
As per your description the answer is A. could you please paste the source of the information.
upvoted 2 times
Nicodebian
3 years, 4 months ago
https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq
upvoted 5 times
...
...
xMilkyMan123
2 years, 9 months ago
https://github.com/MicrosoftDocs/azure-docs/issues/77499 Dont believe everything you read on the internet. Go and test things for yourself. Even Microsoft official articles can misword things sometimes
upvoted 23 times
juniorccs
2 years, 9 months ago
I agree with you
upvoted 2 times
...
IAGirl
1 year, 11 months ago
Pls don't believe everything you read on the internet! To Enable Traffic Analytics your account must be a member of one of the following Azure built-in roles: Owner, Contributor, Reader, Network Contributor or you can create a custom role with the following actions at the subscription level: "Microsoft.Network/applicationGateways/read" "Microsoft.Network/connections/read" "Microsoft.Network/loadBalancers/read" "Microsoft.Network/localNetworkGateways/read" "Microsoft.Network/networkInterfaces/read" "Microsoft.Network/networkSecurityGroups/read" "Microsoft.Network/publicIPAddresses/read" "Microsoft.Network/routeTables/read" "Microsoft.Network/virtualNetworkGateways/read" "Microsoft.Network/virtualNetworks/read" "Microsoft.Network/expressRouteCircuits/read" https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics TESTED
upvoted 10 times
mbaybarsk
1 year, 10 months ago
That's not what the link you've provided say anymore: It now refers to "access" which is not the same thing as "enable".
upvoted 5 times
...
...
...
visave
3 years, 4 months ago
got it. https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq#:~:text=Your%20account%20must%20meet%20one,%2C%20reader%2C%20or%20network%20contributor.
upvoted 7 times
MountainW
3 years ago
The key is to enable, not to use. The article is about to use. The answer is not correct.
upvoted 12 times
JayBee65
2 years, 10 months ago
The requirements above state.. Your account must meet one of the following to ***enable**** traffic analytics: Your account must have any one of the following Azure roles at the subscription scope: owner, contributor, ***reader***, or network contributor. So it is correct
upvoted 10 times
jot2
2 years, 3 months ago
The article is wrong in this case. I tried it out. A user with Reader role can't enable Traffic Analytics.
upvoted 8 times
NadirM_18
2 years ago
According to this link, they can enable Traffic Analytics: https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics
upvoted 1 times
...
...
...
...
...
Chang401
1 year, 6 months ago
agree we can enable TA. use the below link for answer. https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq#what-are-the-prerequisites-to-use-traffic-analytics-
upvoted 3 times
...
...
mlantonis
Highly Voted 2 years, 11 months ago
Correct Answer: A - Yes Your account must have any one of the following Azure roles at the subscription scope: owner, contributor, reader, or network contributor. Reader role - View all resources, but does not allow you to make any changes. Traffic Analytics is a cloud-based solution that provides visibility into user and application activity in cloud networks. Traffic analytics analyzes Network Watcher network security group (NSG) flow logs to provide insights into traffic flow in your Azure cloud. Reference: https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics#user-access-requirements https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
upvoted 93 times
hercu
2 years, 10 months ago
I think the answer is correct as it's assumed that the prerequisites to use traffic analytics are already met. Refering to: https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq#what-are-the-prerequisites-to-use-traffic-analytics- As a result, as stated just few lines below, all following roles: Owner, Contributor, Reader, or Network Contributor are sufficient to enable Traffic Analytics.
upvoted 3 times
...
xupiter
2 years, 10 months ago
"Reader role - View all resources, but does not allow you to make any changes." So that means this role doesn't allow you to enable traffic analytics. So it cannot be "Yes".
upvoted 20 times
Mozbius_
2 years, 3 months ago
Yet it is "Yes". You can blame Microsoft for the confusion. https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq
upvoted 8 times
GoldenDisciple2
8 months, 1 week ago
According to Microsoft, the sky is up, but the answer is down. To Microsoft, the ocean is wet but the answer is dry, the desert is dry but on the exam you must select wet or you'll get it wrong... According to Microsoft, the air in space is breathable... Let me explain. The earth has breathable air and the earth is in space, therefor, the air in space is breathable...
upvoted 9 times
shahidsayyed
6 months ago
You should try standup comedy as an alternative career. Got into wrong profession.
upvoted 2 times
...
...
...
...
...
pverma20
Most Recent 5 days, 5 hours ago
Correct Answer - No (Confirmed, check below documentation) If you enable Traffic Analytics for sure, it require some write access to capture and write the logs. We need to be Logical. https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics Prerequisites Traffic analytics requires the following prerequisites: A Network Watcher enabled subscription. For more information, see Enable or disable Azure Network Watcher. NSG flow logs enabled for the network security groups you want to monitor or VNet flow logs enabled for the virtual network you want to monitor. For more information, see Create a flow log or Enable VNet flow logs. An Azure Log Analytics workspace with read and write access. For more information, see Create a Log Analytics workspace. One of the following Azure built-in roles needs to be assigned to your account: Expand table Deployment model Role Resource Manager Owner Contributor Network contributor 1 and Monitoring contributor 2
upvoted 1 times
...
Annie_5
1 week ago
Selected Answer: B
It seems reader role cannot enable traffic analytics. It can view it.
upvoted 1 times
...
6f80f6c
1 week, 1 day ago
Selected Answer: B
Answer is B, NO. supporting : https://learn.microsoft.com/en-us/answers/questions/1330227/what-role-is-required-to-be-enabled-at-subscriptio
upvoted 1 times
...
Nushin
1 week, 3 days ago
Owner Contributor Network contributor 1 and Monitoring contributor 2
upvoted 1 times
...
Jobalos009
3 weeks, 1 day ago
Selected Answer: B
The answer is B https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics
upvoted 1 times
...
MelKr
4 weeks, 1 day ago
Selected Answer: B
According to current documentation B is correct. https://learn.microsoft.com/en-us/azure/network-watcher/required-rbac-permissions#traffic-analytic: "Since traffic analytics is enabled as part of the Flow log resource, the following permissions are required in addition to all the required permissions for Flow logs". I believe that the permission "Microsoft.Network/networkWatchers/configureFlowLog/action" is not part of the Reader role. Also, "Microsoft.OperationalInsights/workspaces/sharedkeys/action" is not in the Reader role.
upvoted 2 times
...
_gio_
1 month ago
Selected Answer: B
No as explained here: https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics
upvoted 3 times
...
SillyChili
1 month ago
Answer should be B (No). Check out the prerequisite for traffic analytics. Reader role is not there. https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics#prerequisites
upvoted 1 times
...
tashakori
1 month ago
No is right
upvoted 1 times
...
Seppl
1 month, 2 weeks ago
From ChatGPT: No, this solution does not meet the goal. The Reader role at the subscription level in Azure AD allows you to view all resources, but it does not permit write operations, which are required to enable Traffic Analytics1. To enable Traffic Analytics for an Azure subscription, the user needs to have one of the following roles assigned at the subscription level1: Owner Contributor Network Contributor These roles allow the necessary write operations. If none of these roles are suitable, a custom role can be created with the specific permissions needed to enable Traffic Analytics1. Please note that assigning the Reader role will not be sufficient to enable Traffic Analytics1
upvoted 1 times
...
Cg007
1 month, 2 weeks ago
Selected Answer: B
No, assigning the Reader role at the subscription level to Admin1 does not meet the goal of enabling Traffic Analytics for the Azure subscription. The Reader role only grants read-only access to Azure resources, meaning Admin1 would not have the necessary permissions to enable Traffic Analytics or perform any management actions on the subscription.
upvoted 1 times
...
lovekiller
1 month, 2 weeks ago
Selected Answer: B
Answer is NO. As per latest these are the roles needed to be assigned: "Owner" or "Contributor" or "Network Contributor and Monitoring Contributor" Source: https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics#prerequisites
upvoted 1 times
...
eddzequiel
1 month, 2 weeks ago
answer is no
upvoted 1 times
...
gil906
1 month, 3 weeks ago
Selected Answer: B
Answer is No, reader role does not apply: One of the following Azure built-in roles needs to be assigned to your account: * Owner * Contributor * Network contributor and Monitoring contributor Reference https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics#prerequisites
upvoted 4 times
...
gil906
1 month, 3 weeks ago
Selected Answer: A
Answer is yes, To enable Traffic Analytics for an Azure subscription, your account must have one of the following Azure roles assigned at the subscription scope: Owner Contributor Reader Network Contributor
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...