Logging Application of Specific NSG Rules
You have an Azure subscription that contains 100 network security groups (NSGs). You need to ensure that you log the application of specific NSG rules. Which type of log should you configure?
Community Votes
57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Azure resource logs for NSGs capture which specific rule was applied to traffic, whereas NSG flow logs only capture the 5-tuple flow data and the allow/deny outcome without the rule ID.
To log the application of specific NSG rules in Azure, you must configure Azure resource logs, not NSG flow logs. This guide clarifies the distinction between flow logs and resource logs for NSG rule evaluation.
Choosing flow log (A) because it is the most commonly discussed NSG logging feature, but flow logs do not identify the specific rule applied, only the overall allow/deny decision.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Configuring Azure resource logs (Option C) for a Network Security Group enables theNetworkSecurityGroupEvent and NetworkSecurityGroupRuleCounter diagnostic log categories. These categories specifically record which NSG rule was evaluated and applied to a given flow, including the rule ID. This directly satisfies the requirement to log the application of specific NSG rules.Why the Other Options Are Wrong
NSG flow logs (Option A) record the source and destination IP, port, protocol, and whether traffic was allowed or denied, but they do not include the specific NSG rule ID that triggered the decision. The Activity log (Option B) records control-plane operations like creating or modifying an NSG, not the runtime application of rules to traffic. Audit log (Option D) is not a specific, standard log category used for this purpose in Azure NSG logging.Community Comment Notes
Several community members correctly identified that the question asks for the specific rule applied, which flow logs do not provide. As one commenter noted, "Flow log only gives allow or deny by a NSG, but not tell which rule under NSG hit." Another user pointed out that "It's for the 'application' of the NSG rules. Which would be Azure Resource Logs," correctly distinguishing it from traffic flow analysis.Official Reference
Exam Strategy
Pay close attention to whether a question asks for network traffic flow analysis or the specific rule evaluation. If it asks for specific rule IDs or rule application events, choose Azure resource logs; if it asks for 5-tuple traffic flow, choose NSG flow logs.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →