Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are deploying an Azure SQL Managed Instance in a dedicated subnet. To meet corporate policy you attach a Network Security Group (NSG) to the subnet and delete the default Allow Internet Outbound rule, effectively blocking all outbound Internet traffic. After the change, the managed instance remains stuck in the Creating state and eventually fails to provision. You must keep the Internet block in place but still allow the managed instance to deploy and operate. Which single NSG rule should you add?
Allow outbound TCP 1443 to the service tag VirtualNetwork
Allow outbound TCP 443 to the service tag Internet
Allow outbound UDP 1194 to the service tag GatewayManager
Allow outbound TCP 443 to the service tag SqlManagement
Azure SQL Managed Instance relies on Azure-hosted management endpoints that are not reachable through the local virtual network. Microsoft exposes the required addresses through the service tag "SqlManagement" and communicates with them over TCP port 443. If outbound traffic to that tag is blocked, provisioning and subsequent management operations (for example, automated patching) fail. Allowing outbound TCP 443 to the SqlManagement service tag opens only the minimum set of addresses required for the service while continuing to deny all other Internet traffic, so the managed instance can deploy and remain compliant with the security policy. The other options either target the wrong port, an unrelated service tag, or would reopen general Internet access, which violates the policy.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a service tag in Azure?
Open an interactive chat with Bash
Why does Azure SQL Managed Instance require access to SqlManagement over TCP 443?
Open an interactive chat with Bash
How does allowing outbound TCP 443 to SqlManagement maintain security while enabling Azure SQL Managed Instance to function?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .