Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AZ-104 topic 11 question 3 discussion

Actual exam question from Microsoft's AZ-104
Question #: 3
Topic #: 11
[All AZ-104 Questions]

You need to identify which storage account to use for the flow logging of IP traffic from VM5. The solution must meet the retention requirements.
Which storage account should you identify?

  • A. storage1
  • B. storage2
  • C. storage3
  • D. storage4
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
We use the BlobStorage account storage3 for retention.
Storage lifecycle management offers a rule-based policy that you can use to transition blob data to the appropriate access tiers or to expire data at the end of the data lifecycle.
Note: Enable flow logging for IP traffic from VM5 and retain the flow logs for a period of eight months.

Reference:
https://docs.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-overview https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alirasouli
Highly Voted 1 year, 5 months ago
Selected Answer: B
For at least two reasons, storage2 is the only candidate: - Location: The storage account used must be in the same region as the NSG. - Retention is available only if you use General Purpose v2 Storage accounts (GPv2). Reference: https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview
upvoted 64 times
BobbyMc3030
10 months, 2 weeks ago
I agree that the answer is B. Documentation clearly states only General Purpose V2 Storage supports retention. It also states that the storage must be in the same location as the nsg. That much I get. But can someone explain to me how the NSG being in the same region as the storage applies to this question? I only see mention of 2 NSGs in the example and neither are applied to VNET 4 where VM 5 is. As far as I can tell, only the storage type is relevant to this question. I’m open to being wrong if someone can explain it. Thanks.
upvoted 6 times
macinpune9
9 months ago
location of NSG looks irrelevant as both NSGs are in west UA while storage2 is in east us
upvoted 3 times
...
...
Panapi
1 year, 1 month ago
Answer valid! This question was on the exam 22/02/2023. Scored 920. Thanks guys!
upvoted 9 times
...
go4adil
2 months, 3 weeks ago
Correct Answer is: B (Storage 2) Network Watcher 'Flow Logs' tool is used to log information about Azure IP traffic and stores the data in Azure storage. You can log IP traffic using either of the two following tools: i. NSG Flow Logs (log information about IP traffic flowing through a network security group) or ii. VNET Flow Logs (log information about IP traffic flowing through a virtual network) It is to be noted that NSG flow logs have a retention feature that allows deleting the logs automatically up to a year after their creation. Retention is available only if you use general-purpose v2 storage accounts. So, despite the fact that there is no mention of NSG for VM5, in order to make use of retention feature, NSG flow must be implemented which would need GPv2 storage account. Also, VNET Flow logs is currently in Preview and is not recommended for Production workloads. Ref: https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview
upvoted 1 times
...
...
Koyegunle
Highly Voted 9 months, 2 weeks ago
This scenario was my first set of questions yesterday 7th July 2023. Thanks to all the knowledgeable contributors and those to did lab tests to help confirm the right answers. I successfully aced it with 896 score. Going for the 305 now.
upvoted 12 times
...
tashakori
Most Recent 1 month ago
B is right
upvoted 1 times
...
vroh
6 months, 3 weeks ago
Got this question on Sep25 and this was the first question in exam!
upvoted 4 times
...
oopspruu
8 months ago
Selected Answer: B
B is the correct answer. Keyword is "retention"
upvoted 2 times
...
profesorklaus
8 months ago
I tried it in my lab. With storage account v2 retentiuon policy - no issues. When tried with V2 then message comes up - "Retention is only available with v2 Storage accounts.Learn more about retention policy."
upvoted 1 times
...
Janal
8 months, 3 weeks ago
Answer B is correct Blob Storage accounts in Azure do not support flow logging for 365 days. Flow logging for Blob Storage accounts has a retention period of 30 days. This means that the flow log data is retained for only 30 days before being automatically deleted. If you need to retain flow log data for a longer period and that is what we need 8 months, you may consider using General Purpose v2 (GPv2) storage accounts instead, which support flow logging with a retention period of up to 365 days.
upvoted 2 times
...
Pakawat
9 months, 3 weeks ago
Found this Q in the exam 3/7/2023
upvoted 1 times
...
abdelmim
11 months, 3 weeks ago
C is correct answer Location: The storage account used must be in the same region as the network security group. Performance tier: Currently, only standard-tier storage accounts are supported. we dont need GPv2 account because it not supported yet
upvoted 1 times
...
kmsalman
11 months, 3 weeks ago
Azure Blob storage is the right option. You can use immutable backup feature to enable retention in Azure Blob storage.
upvoted 1 times
...
zzreflexzz
11 months, 3 weeks ago
on exam 4/29/23
upvoted 2 times
...
CyberKelev
1 year, 1 month ago
Selected Answer: B
The correct answer is B. Storage2. Storage2 is a General Purpose v2 storage account, which supports the retention of logs for up to 365 days. Storage1 is a General Purpose v1 storage account, which supports the retention of logs for up to 30 days. Storage3 is a Blob storage account, which does not support flow logging. Storage4 is a File storage account, which does not support flow logging either.
upvoted 6 times
...
SumanSaurabh
1 year, 4 months ago
Correct answer is B Retention is available only if you use General Purpose v2 Storage accounts (GPv2)
upvoted 1 times
...
wolf13
1 year, 4 months ago
Selected Answer: B
I agree with the answer given by Alirasouli. This question appears in case study: Contoso LTD, Consulting Conpany
upvoted 1 times
...
Mev4953
1 year, 7 months ago
Answer is B Retention is available only if you use General purpose v2 Storage accounts (GPv2). https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview#how-logging-works:~:text=Retention%20is%20available%20only%20if%20you%20use%20General%20purpose%20v2%20Storage%20accounts%20(GPv2).
upvoted 3 times
...
EleChie
1 year, 7 months ago
Correct Answer is: B "Retention is available only if you use General purpose v2 Storage accounts (GPv2)" Reference: https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview#how-logging-works
upvoted 4 times
...
lebowski
1 year, 7 months ago
Selected Answer: B
"Retention is available only if you use General purpose v2 Storage accounts (GPv2)" https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview#how-logging-works
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...