AZ-011 Microsoft Azure

NSG flow logs are enabled.

NSG flow logs are enabled.

Domain
Microsoft Azure
Area
Networking
Automated / manual
Automated

Risk if it fails

No network telemetry = blind to attacks.

Without flow logs you cannot see suspicious connections or data leaving your network — you lose the ability to detect and investigate intrusions.

How Tess tests it

1 test — each concludes only on cited evidence.

NSG flow logs are enabled.

Automated
Procedure
Confirm flow logs configured on NSGs via Network Watcher.

Read-only command

az network watcher flow-log list --location <region> -o table

More in Microsoft Azure

Want Tess to test AZ-011 against your evidence?

Book a demo