Azure Traffic Analytics Aggregated Flow Entries
You have an Azure subscription that contains the resources shown in the following table. NSG1 is associated to the NIC of VM1 and contains the rules shown in the following table. You collect NSG flow logs for five minutes for the following activities: • Two RDP sessions from VM1 to VM2, each initiated from a different TCP port • Three SSH sessions from VM2 to VM1, each initiated from a different TCP port You analyze the logs by using Traffic Analytics in Azure Network Watcher. How many aggregated flow entries will Traffic Analytics identify? -
- 
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Traffic Analytics reduces log volume by aggregating flows with common source IP, destination IP, destination port, and protocol, rather than logging every individual packet or session instance separately.
This question tests how Azure Network Watcher's Traffic Analytics aggregates NSG flow logs. The correct answer is C (5), as the service groups flows by unique source/destination IP and port combinations, resulting in two RDP entries and three SSH entries.
Candidates often choose D (10) by counting each individual connection attempt as a separate entry, failing to realize that Traffic Analytics aggregates these into fewer logical flow records based on the five-tuple.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Traffic Analytics aggregates raw NSG flow logs into summary records. A single aggregated flow entry represents all packets sharing the same five-tuple: Source IP, Destination IP, Source Port, Destination Port, and Protocol. In this scenario, there are two distinct RDP sessions from VM1 to VM2 initiated from different source ports; since the source ports differ, these create two separate aggregated flow entries. Similarly, there are three SSH sessions from VM2 to VM1, each from a different source port, creating three additional entries. Therefore, 2 + 3 = 5 aggregated flow entries.Why the Other Options Are Wrong
Option A (1) is incorrect because it assumes all traffic is merged into a single record regardless of port differences. Option B (2) incorrectly counts only the RDP sessions or the unique destination ports while ignoring the directionality or source port changes for SSH. Option D (10) is the result of misinterpreting the question as asking for total connection attempts without aggregation, or perhaps counting both directions for each session incorrectly.Community Comment Notes
The community consensus strongly supports answer C. Users noted that "NSG flow logs capture each unique flow" defined by the five-tuple. One commenter explained that "Traffic analytics... reduces the log volume by aggregating flows that have a common source IP address, destination IP address, destination port, and protocol." Another user broke down the math clearly: "Two RDP sessions... Total RDP flow entries: 2" and "Three SSH sessions... Total SSH flow entries: 3", summing to 5.Official Reference
Exam Strategy
When dealing with Traffic Analytics questions, always look for unique combinations of IPs and Ports. Do not count every packet or session instance; instead, group them by their unique five-tuple signature to find the number of aggregated entries.
Frequently Asked Questions
Does Traffic Analytics aggregate by destination port only?
No. It aggregates by the full five-tuple including Source IP, Destination IP, Source Port, Destination Port, and Protocol.
Why are different source ports significant?
Different source ports mean the connections are distinct flows. Even if destination IPs/ports are the same, differing source ports create separate aggregated entries.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →