Logging Application of Specific NSG Rules

Implement and manage network security groups
Answer Correct answer: C — Configure Azure resource log to log the application of specific NSG rules.

You have an Azure subscription that contains 100 network security groups (NSGs). You need to ensure that you log the application of specific NSG rules. Which type of log should you configure?

  1. flow log
  2. activity log
  3. Azure resource log Correct Answer
  4. audit log

Community Votes

A
57%
C
43%

57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Azure resource logs for NSGs capture which specific rule was applied to traffic, whereas NSG flow logs only capture the 5-tuple flow data and the allow/deny outcome without the rule ID.

To log the application of specific NSG rules in Azure, you must configure Azure resource logs, not NSG flow logs. This guide clarifies the distinction between flow logs and resource logs for NSG rule evaluation.

Choosing flow log (A) because it is the most commonly discussed NSG logging feature, but flow logs do not identify the specific rule applied, only the overall allow/deny decision.

Community Discussion (7 comments)

e6d6bf4 👍 7 Selected: C
https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-nsg-manage-log The question is asking to enable logging to collect rules applies to traffic that got blocked or allow. Answer is C. Azure Resource Log "A network security group (NSG) includes rules that allow or deny traffic to a virtual network subnet, network interface, or both. When you enable logging for an NSG, you can gather the following types of resource log information: Event: Entries are logged for which NSG rules are applied to virtual machines, based on a MAC address. Rule counter: Contains entries for how many times each NSG rule is applied to allow or deny traffic. The status for these rules is collected every 300 seconds."
ITrob523 👍 1 Selected: C
It's for the "application" of the NSG rules. Which would be Azure Resource Logs. It's not asking for traffic flow... It's asking about knowing when or who applied an NSG which would be resource logs. Don't be fooled by the trick wording here.
tc0369 👍 1 Selected: C
Should be C. Keyword- the question is asking "the specific NSG Rules"! Flow log only gives allow or deny by a NSG, but not tell which rule under NSG hit.
gaurav4101 👍 2 Selected: A
Flow logs is correct. ----------------------- Identify unknown or undesired traffic. Monitor traffic levels and bandwidth consumption. Filter flow logs by IP and port to understand application behavior. Export flow logs to analytics and visualization tools of your choice to set up monitoring dashboards. https://learn.microsoft.com/en-us/azure/network-watcher/nsg-flow-logs-overview#common-use-cases ================== Azure resource logs are platform logs that provide insight into operations that are performed in an Azure resource. https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/resource-logs
manhattan 👍 3 Selected: A
I don't think you need something fancy here, just port and protocol to identify the application logs with trhe regular Azure NSG flow logs. https://learn.microsoft.com/en-us/azure/network-watcher/nsg-flow-logs-overview#common-use-cases Common use cases: Filter flow logs by IP and port to understand application behavior.
alexastein 👍 3 Selected: A
https://learn.microsoft.com/en-us/azure/network-watcher/nsg-flow-logs-overview
ashaw20 👍 4 Selected: A
Flow logs collects ingress/egress IP packets which flows through your NSG (primary objective is to analyze network traffic). Azure Resource logs provides Diagnostics log as it contains higher-level abstraction of log entity i.e. they provide log details are tenant/resource group (or resources) scope. Flow logs is the correct answer since we need to ensure the application of the NSG rules. We don't need to diagnose in details.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Configuring Azure resource logs (Option C) for a Network Security Group enables the NetworkSecurityGroupEvent and NetworkSecurityGroupRuleCounter diagnostic log categories. These categories specifically record which NSG rule was evaluated and applied to a given flow, including the rule ID. This directly satisfies the requirement to log the application of specific NSG rules.

Why the Other Options Are Wrong

NSG flow logs (Option A) record the source and destination IP, port, protocol, and whether traffic was allowed or denied, but they do not include the specific NSG rule ID that triggered the decision. The Activity log (Option B) records control-plane operations like creating or modifying an NSG, not the runtime application of rules to traffic. Audit log (Option D) is not a specific, standard log category used for this purpose in Azure NSG logging.

Community Comment Notes

Several community members correctly identified that the question asks for the specific rule applied, which flow logs do not provide. As one commenter noted, "Flow log only gives allow or deny by a NSG, but not tell which rule under NSG hit." Another user pointed out that "It's for the 'application' of the NSG rules. Which would be Azure Resource Logs," correctly distinguishing it from traffic flow analysis.

Official Reference

Exam Strategy

Pay close attention to whether a question asks for network traffic flow analysis or the specific rule evaluation. If it asks for specific rule IDs or rule application events, choose Azure resource logs; if it asks for 5-tuple traffic flow, choose NSG flow logs.

Related Analysis

Practice All AZ-700 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-700 Practice Test →

← Back to AZ-700 Study Guide