Microsoft Azure Administrator Associate AZ-104 Practice Question
Your company's Azure environment includes several virtual machines that support different application workloads within the same virtual network. You need to manage network security by grouping virtual machines based on their application roles to simplify the management of inbound and outbound traffic rules. What is the best way to achieve this goal?
Use application security groups to group the virtual machines and apply network security group rules to these groups.
Implement Azure Firewall to control traffic to the virtual machines.
Place each application workload in a separate subnet and associate a network security group with each subnet.
Assign the same network security group to all virtual machines.