Microsoft AZ-104 Azure Network Watcher Practice Test

 

Topic 19 focuses on Azure Network Watcher and Connection Monitor for the Microsoft Certified: Azure Administrator Associate certification and the AZ-104 exam, using Microsoft Azure administration scenarios. For broader exam preparation, review the Microsoft Azure Administrator AZ-104 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

To troubleshoot and observe Azure virtual-network connectivity, which Azure configuration should be selected?

  1. VPN troubleshoot
  2. Azure Network Watcher
  3. Virtual network flow logs
  4. Network topology

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure Network Watcher is the Azure network monitoring and diagnostic service that provides tools for connectivity, routing, packet, and topology analysis. It directly supports the requirement to troubleshoot and observe Azure virtual-network connectivity.

Incorrect Answers

Answer A is incorrect because VPN troubleshoot is used to collect diagnostic information for site-to-site VPN connectivity issues; it does not provide the capability described in the scenario.

Answer C is incorrect because Virtual network flow logs is used to analyze network-flow patterns and support traffic visibility over time; it does not provide the capability described in the scenario.

Answer D is incorrect because Network topology is used to understand how Azure networking components are connected; it does not provide the capability described in the scenario.

 

Question 2

For Azure Network Watcher, which administrative outcome is expected?

  1. Collect diagnostic information for site-to-site VPN connectivity issues
  2. Verify combined subnet and NIC security filtering during network troubleshooting
  3. Monitor end-to-end reachability and latency over time instead of running only a one-time test
  4. Troubleshoot and observe Azure virtual-network connectivity

Correct Answer: D

 

Correct Answer

Answer D is correct because Azure Network Watcher is the Azure network monitoring and diagnostic service that provides tools for connectivity, routing, packet, and topology analysis. Its intended administrative use is to troubleshoot and observe Azure virtual-network connectivity.

Incorrect Answers

Answer A is incorrect because that outcome belongs to VPN troubleshoot, which is used to collect diagnostic information for site-to-site VPN connectivity issues; it is not the primary purpose of Azure Network Watcher.

Answer B is incorrect because that outcome belongs to Effective security rules view, which is used to verify combined subnet and NIC security filtering during network troubleshooting; it is not the primary purpose of Azure Network Watcher.

Answer C is incorrect because that outcome belongs to Connection Monitor, which is used to monitor end-to-end reachability and latency over time instead of running only a one-time test; it is not the primary purpose of Azure Network Watcher.

 

Question 3

To monitor end-to-end reachability and latency over time instead of running only a one-time test, which Azure configuration should be selected?

  1. Connection Monitor
  2. VPN troubleshoot
  3. Connection troubleshoot
  4. Next hop

Correct Answer: A

 

Correct Answer

Answer A is correct because Connection Monitor is a Network Watcher capability that continuously tests and records connectivity between configured source and destination endpoints. It directly supports the requirement to monitor end-to-end reachability and latency over time instead of running only a one-time test.

Incorrect Answers

Answer B is incorrect because VPN troubleshoot is used to collect diagnostic information for site-to-site VPN connectivity issues; it does not provide the capability described in the scenario.

Answer C is incorrect because Connection troubleshoot is used to investigate a specific connectivity failure interactively; it does not provide the capability described in the scenario.

Answer D is incorrect because Next hop is used to determine whether routing sends traffic to the expected gateway, appliance, internet, or other path; it does not provide the capability described in the scenario.

 

Question 4

For Connection Monitor, which administrative outcome is expected?

  1. Collect diagnostic information for site-to-site VPN connectivity issues
  2. Monitor end-to-end reachability and latency over time instead of running only a one-time test
  3. Inspect actual network traffic when higher-level diagnostics are insufficient
  4. Determine whether routing sends traffic to the expected gateway, appliance, internet, or other path

Correct Answer: B

 

Correct Answer

Answer B is correct because Connection Monitor is a Network Watcher capability that continuously tests and records connectivity between configured source and destination endpoints. Its intended administrative use is to monitor end-to-end reachability and latency over time instead of running only a one-time test.

Incorrect Answers

Answer A is incorrect because that outcome belongs to VPN troubleshoot, which is used to collect diagnostic information for site-to-site VPN connectivity issues; it is not the primary purpose of Connection Monitor.

Answer C is incorrect because that outcome belongs to Packet capture, which is used to inspect actual network traffic when higher-level diagnostics are insufficient; it is not the primary purpose of Connection Monitor.

Answer D is incorrect because that outcome belongs to Next hop, which is used to determine whether routing sends traffic to the expected gateway, appliance, internet, or other path; it is not the primary purpose of Connection Monitor.

 

Question 5

To identify which NSG rule permits or blocks a specified flow, which Azure configuration should be selected?

  1. VPN troubleshoot
  2. Azure Network Watcher
  3. IP flow verify
  4. Next hop

Correct Answer: C

 

Correct Answer

Answer C is correct because IP flow verify is a Network Watcher diagnostic that tests whether a hypothetical packet to or from a VM would be allowed or denied by applicable NSG rules. It directly supports the requirement to identify which NSG rule permits or blocks a specified flow.

Incorrect Answers

Answer A is incorrect because VPN troubleshoot is used to collect diagnostic information for site-to-site VPN connectivity issues; it does not provide the capability described in the scenario.

Answer B is incorrect because Azure Network Watcher is used to troubleshoot and observe Azure virtual-network connectivity; it does not provide the capability described in the scenario.

Answer D is incorrect because Next hop is used to determine whether routing sends traffic to the expected gateway, appliance, internet, or other path; it does not provide the capability described in the scenario.

 

Question 6

For IP flow verify, which administrative outcome is expected?

  1. Inspect actual network traffic when higher-level diagnostics are insufficient
  2. Identify which NSG rule permits or blocks a specified flow
  3. Troubleshoot and observe Azure virtual-network connectivity
  4. Determine whether routing sends traffic to the expected gateway, appliance, internet, or other path

Correct Answer: B

 

Correct Answer

Answer B is correct because IP flow verify is a Network Watcher diagnostic that tests whether a hypothetical packet to or from a VM would be allowed or denied by applicable NSG rules. Its intended administrative use is to identify which NSG rule permits or blocks a specified flow.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Packet capture, which is used to inspect actual network traffic when higher-level diagnostics are insufficient; it is not the primary purpose of IP flow verify.

Answer C is incorrect because that outcome belongs to Azure Network Watcher, which is used to troubleshoot and observe Azure virtual-network connectivity; it is not the primary purpose of IP flow verify.

Answer D is incorrect because that outcome belongs to Next hop, which is used to determine whether routing sends traffic to the expected gateway, appliance, internet, or other path; it is not the primary purpose of IP flow verify.

 

Question 7

To determine whether routing sends traffic to the expected gateway, appliance, internet, or other path, which Azure configuration should be selected?

  1. Connection troubleshoot
  2. VPN troubleshoot
  3. Next hop
  4. Azure Network Watcher

Correct Answer: C

 

Correct Answer

Answer C is correct because Next hop is a Network Watcher diagnostic that reports the route and next-hop type Azure would use for traffic from a VM to a destination. It directly supports the requirement to determine whether routing sends traffic to the expected gateway, appliance, internet, or other path.

Incorrect Answers

Answer A is incorrect because Connection troubleshoot is used to investigate a specific connectivity failure interactively; it does not provide the capability described in the scenario.

Answer B is incorrect because VPN troubleshoot is used to collect diagnostic information for site-to-site VPN connectivity issues; it does not provide the capability described in the scenario.

Answer D is incorrect because Azure Network Watcher is used to troubleshoot and observe Azure virtual-network connectivity; it does not provide the capability described in the scenario.

 

Question 8

For Next hop, which administrative outcome is expected?

  1. Inspect actual network traffic when higher-level diagnostics are insufficient
  2. Troubleshoot and observe Azure virtual-network connectivity
  3. Monitor end-to-end reachability and latency over time instead of running only a one-time test
  4. Determine whether routing sends traffic to the expected gateway, appliance, internet, or other path

Correct Answer: D

 

Correct Answer

Answer D is correct because Next hop is a Network Watcher diagnostic that reports the route and next-hop type Azure would use for traffic from a VM to a destination. Its intended administrative use is to determine whether routing sends traffic to the expected gateway, appliance, internet, or other path.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Packet capture, which is used to inspect actual network traffic when higher-level diagnostics are insufficient; it is not the primary purpose of Next hop.

Answer B is incorrect because that outcome belongs to Azure Network Watcher, which is used to troubleshoot and observe Azure virtual-network connectivity; it is not the primary purpose of Next hop.

Answer C is incorrect because that outcome belongs to Connection Monitor, which is used to monitor end-to-end reachability and latency over time instead of running only a one-time test; it is not the primary purpose of Next hop.

 

Question 9

To investigate a specific connectivity failure interactively, which Azure configuration should be selected?

  1. Packet capture
  2. IP flow verify
  3. Connection Monitor
  4. Connection troubleshoot

Correct Answer: D

 

Correct Answer

Answer D is correct because Connection troubleshoot is a Network Watcher point-in-time diagnostic that tests reachability from a source to a destination and reports likely failure information. It directly supports the requirement to investigate a specific connectivity failure interactively.

Incorrect Answers

Answer A is incorrect because Packet capture is used to inspect actual network traffic when higher-level diagnostics are insufficient; it does not provide the capability described in the scenario.

Answer B is incorrect because IP flow verify is used to identify which NSG rule permits or blocks a specified flow; it does not provide the capability described in the scenario.

Answer C is incorrect because Connection Monitor is used to monitor end-to-end reachability and latency over time instead of running only a one-time test; it does not provide the capability described in the scenario.

 

Question 10

A single Azure VM cannot reach a known destination. The administrator runs Connection troubleshoot for that source and destination. What is the specific purpose of this point-in-time test?

  1. Investigate a specific connectivity failure interactively
  2. Collect diagnostic information for site-to-site VPN connectivity issues
  3. Troubleshoot and observe Azure virtual-network connectivity
  4. Determine whether routing sends traffic to the expected gateway, appliance, internet, or other path

Correct Answer: A

 

Correct Answer

Answer A is correct because Connection troubleshoot is a Network Watcher point-in-time diagnostic that tests reachability from a source to a destination and reports likely failure information. Its intended administrative use is to investigate a specific connectivity failure interactively.

Incorrect Answers

Answer B is incorrect because that outcome belongs to VPN troubleshoot, which is used to collect diagnostic information for site-to-site VPN connectivity issues; it is not the primary purpose of Connection troubleshoot.

Answer C is incorrect because that outcome belongs to Azure Network Watcher, which is used to troubleshoot and observe Azure virtual-network connectivity; it is not the primary purpose of Connection troubleshoot.

Answer D is incorrect because that outcome belongs to Next hop, which is used to determine whether routing sends traffic to the expected gateway, appliance, internet, or other path; it is not the primary purpose of Connection troubleshoot.

 

Question 11

To inspect actual network traffic when higher-level diagnostics are insufficient, which Azure configuration should be selected?

  1. Connection Monitor
  2. Packet capture
  3. Virtual network flow logs
  4. VPN troubleshoot

Correct Answer: B

 

Correct Answer

Answer B is correct because Packet capture is a Network Watcher capability that captures packets from a supported Azure VM based on configured filters. It directly supports the requirement to inspect actual network traffic when higher-level diagnostics are insufficient.

Incorrect Answers

Answer A is incorrect because Connection Monitor is used to monitor end-to-end reachability and latency over time instead of running only a one-time test; it does not provide the capability described in the scenario.

Answer C is incorrect because Virtual network flow logs is used to analyze network-flow patterns and support traffic visibility over time; it does not provide the capability described in the scenario.

Answer D is incorrect because VPN troubleshoot is used to collect diagnostic information for site-to-site VPN connectivity issues; it does not provide the capability described in the scenario.

 

Question 12

For Packet capture, which administrative outcome is expected?

  1. Investigate a specific connectivity failure interactively
  2. Troubleshoot and observe Azure virtual-network connectivity
  3. Inspect actual network traffic when higher-level diagnostics are insufficient
  4. Collect diagnostic information for site-to-site VPN connectivity issues

Correct Answer: C

 

Correct Answer

Answer C is correct because Packet capture is a Network Watcher capability that captures packets from a supported Azure VM based on configured filters. Its intended administrative use is to inspect actual network traffic when higher-level diagnostics are insufficient.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Connection troubleshoot, which is used to investigate a specific connectivity failure interactively; it is not the primary purpose of Packet capture.

Answer B is incorrect because that outcome belongs to Azure Network Watcher, which is used to troubleshoot and observe Azure virtual-network connectivity; it is not the primary purpose of Packet capture.

Answer D is incorrect because that outcome belongs to VPN troubleshoot, which is used to collect diagnostic information for site-to-site VPN connectivity issues; it is not the primary purpose of Packet capture.

 

Question 13

To understand how Azure networking components are connected, which Azure configuration should be selected?

  1. Connection troubleshoot
  2. Next hop
  3. Network topology
  4. Packet capture

Correct Answer: C

 

Correct Answer

Answer C is correct because Network topology is a Network Watcher view that represents relationships between supported network resources in a selected scope or topology experience. It directly supports the requirement to understand how Azure networking components are connected.

Incorrect Answers

Answer A is incorrect because Connection troubleshoot is used to investigate a specific connectivity failure interactively; it does not provide the capability described in the scenario.

Answer B is incorrect because Next hop is used to determine whether routing sends traffic to the expected gateway, appliance, internet, or other path; it does not provide the capability described in the scenario.

Answer D is incorrect because Packet capture is used to inspect actual network traffic when higher-level diagnostics are insufficient; it does not provide the capability described in the scenario.

 

Question 14

For Network topology, which administrative outcome is expected?

  1. Understand how Azure networking components are connected
  2. Inspect actual network traffic when higher-level diagnostics are insufficient
  3. Troubleshoot and observe Azure virtual-network connectivity
  4. Identify which NSG rule permits or blocks a specified flow

Correct Answer: A

 

Correct Answer

Answer A is correct because Network topology is a Network Watcher view that represents relationships between supported network resources in a selected scope or topology experience. Its intended administrative use is to understand how Azure networking components are connected.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Packet capture, which is used to inspect actual network traffic when higher-level diagnostics are insufficient; it is not the primary purpose of Network topology.

Answer C is incorrect because that outcome belongs to Azure Network Watcher, which is used to troubleshoot and observe Azure virtual-network connectivity; it is not the primary purpose of Network topology.

Answer D is incorrect because that outcome belongs to IP flow verify, which is used to identify which NSG rule permits or blocks a specified flow; it is not the primary purpose of Network topology.

 

Question 15

To collect diagnostic information for site-to-site VPN connectivity issues, which Azure configuration should be selected?

  1. Effective security rules view
  2. VPN troubleshoot
  3. IP flow verify
  4. Connection Monitor

Correct Answer: B

 

Correct Answer

Answer B is correct because VPN troubleshoot is a Network Watcher diagnostic for supported virtual network gateway and connection problems. It directly supports the requirement to collect diagnostic information for site-to-site VPN connectivity issues.

Incorrect Answers

Answer A is incorrect because Effective security rules view is used to verify combined subnet and NIC security filtering during network troubleshooting; it does not provide the capability described in the scenario.

Answer C is incorrect because IP flow verify is used to identify which NSG rule permits or blocks a specified flow; it does not provide the capability described in the scenario.

Answer D is incorrect because Connection Monitor is used to monitor end-to-end reachability and latency over time instead of running only a one-time test; it does not provide the capability described in the scenario.

 

Question 16

For VPN troubleshoot, which administrative outcome is expected?

  1. Collect diagnostic information for site-to-site VPN connectivity issues
  2. Troubleshoot and observe Azure virtual-network connectivity
  3. Analyze network-flow patterns and support traffic visibility over time
  4. Inspect actual network traffic when higher-level diagnostics are insufficient

Correct Answer: A

 

Correct Answer

Answer A is correct because VPN troubleshoot is a Network Watcher diagnostic for supported virtual network gateway and connection problems. Its intended administrative use is to collect diagnostic information for site-to-site VPN connectivity issues.

Incorrect Answers

Answer B is incorrect because that outcome belongs to Azure Network Watcher, which is used to troubleshoot and observe Azure virtual-network connectivity; it is not the primary purpose of VPN troubleshoot.

Answer C is incorrect because that outcome belongs to Virtual network flow logs, which is used to analyze network-flow patterns and support traffic visibility over time; it is not the primary purpose of VPN troubleshoot.

Answer D is incorrect because that outcome belongs to Packet capture, which is used to inspect actual network traffic when higher-level diagnostics are insufficient; it is not the primary purpose of VPN troubleshoot.

 

Question 17

To verify combined subnet and NIC security filtering during network troubleshooting, which Azure configuration should be selected?

  1. Effective security rules view
  2. Connection Monitor
  3. IP flow verify
  4. Network topology

Correct Answer: A

 

Correct Answer

Answer A is correct because Effective security rules view is the Network Watcher or NIC-level view of the NSG rules actually affecting a VM network interface. It directly supports the requirement to verify combined subnet and NIC security filtering during network troubleshooting.

Incorrect Answers

Answer B is incorrect because Connection Monitor is used to monitor end-to-end reachability and latency over time instead of running only a one-time test; it does not provide the capability described in the scenario.

Answer C is incorrect because IP flow verify is used to identify which NSG rule permits or blocks a specified flow; it does not provide the capability described in the scenario.

Answer D is incorrect because Network topology is used to understand how Azure networking components are connected; it does not provide the capability described in the scenario.

 

Question 18

A VM has NSGs associated with both its subnet and its network interface. What should the administrator use the Effective security rules view to verify?

  1. Troubleshoot and observe Azure virtual-network connectivity
  2. Identify which NSG rule permits or blocks a specified flow
  3. Collect diagnostic information for site-to-site VPN connectivity issues
  4. Verify combined subnet and NIC security filtering during network troubleshooting

Correct Answer: D

 

Correct Answer

Answer D is correct because Effective security rules view is the Network Watcher or NIC-level view of the NSG rules actually affecting a VM network interface. Its intended administrative use is to verify combined subnet and NIC security filtering during network troubleshooting.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Azure Network Watcher, which is used to troubleshoot and observe Azure virtual-network connectivity; it is not the primary purpose of Effective security rules view.

Answer B is incorrect because that outcome belongs to IP flow verify, which is used to identify which NSG rule permits or blocks a specified flow; it is not the primary purpose of Effective security rules view.

Answer C is incorrect because that outcome belongs to VPN troubleshoot, which is used to collect diagnostic information for site-to-site VPN connectivity issues; it is not the primary purpose of Effective security rules view.

 

Question 19

To analyze network-flow patterns and support traffic visibility over time, which Azure configuration should be selected?

  1. Effective security rules view
  2. VPN troubleshoot
  3. Virtual network flow logs
  4. Azure Network Watcher

Correct Answer: C

 

Correct Answer

Answer C is correct because Virtual network flow logs is flow telemetry that records IP traffic information for virtual networks using the current flow-log capability. It directly supports the requirement to analyze network-flow patterns and support traffic visibility over time.

Incorrect Answers

Answer A is incorrect because Effective security rules view is used to verify combined subnet and NIC security filtering during network troubleshooting; it does not provide the capability described in the scenario.

Answer B is incorrect because VPN troubleshoot is used to collect diagnostic information for site-to-site VPN connectivity issues; it does not provide the capability described in the scenario.

Answer D is incorrect because Azure Network Watcher is used to troubleshoot and observe Azure virtual-network connectivity; it does not provide the capability described in the scenario.

 

Question 20

For Virtual network flow logs, which administrative outcome is expected?

  1. Verify combined subnet and NIC security filtering during network troubleshooting
  2. Inspect actual network traffic when higher-level diagnostics are insufficient
  3. Collect diagnostic information for site-to-site VPN connectivity issues
  4. Analyze network-flow patterns and support traffic visibility over time

Correct Answer: D

 

Correct Answer

Answer D is correct because Virtual network flow logs is flow telemetry that records IP traffic information for virtual networks using the current flow-log capability. Its intended administrative use is to analyze network-flow patterns and support traffic visibility over time.

Incorrect Answers

Answer A is incorrect because that outcome belongs to Effective security rules view, which is used to verify combined subnet and NIC security filtering during network troubleshooting; it is not the primary purpose of Virtual network flow logs.

Answer B is incorrect because that outcome belongs to Packet capture, which is used to inspect actual network traffic when higher-level diagnostics are insufficient; it is not the primary purpose of Virtual network flow logs.

Answer C is incorrect because that outcome belongs to VPN troubleshoot, which is used to collect diagnostic information for site-to-site VPN connectivity issues; it is not the primary purpose of Virtual network flow logs.

 

img