Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Subnet1 of an Azure virtual network is associated to an NSG that currently contains the default rules plus a custom inbound rule that allows TCP 443 from any source with priority 200. You must prevent the public IP address 203.0.113.7 from reaching resources in Subnet1 on port 443 while preserving HTTPS access for all other clients. Which change should you make to the NSG?
Modify the existing allow rule by changing the source to IP Addresses and specifying every public range except 203.0.113.7.
Change the existing allow rule to priority 100 and add a new deny-all rule for TCP 443 at priority 300.
Add a new inbound security rule with priority 300 that denies TCP 443 traffic from source IP address 203.0.113.7.
Add a new inbound security rule with priority 100 that denies TCP 443 traffic from source IP address 203.0.113.7.
Network security group rules are processed in ascending order of priority; the first matching rule ends evaluation. Adding a deny rule for TCP 443 from source IP 203.0.113.7 with a priority lower than 200 guarantees that traffic from that address is blocked before the existing allow rule is reached. Creating the rule with a priority of 100 meets this requirement. A deny rule with priority 300 would be ignored because the earlier allow rule already matched the traffic. Modifying the existing allow rule to exclude a single address is not supported, and replacing the allow rule with a broader deny rule would block all HTTPS traffic, not just the unwanted IP.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Network Security Group (NSG)?
Open an interactive chat with Bash
How does priority affect NSG rules?
Open an interactive chat with Bash
What happens if multiple rules apply to the same traffic in an NSG?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .