Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You are deploying an Azure SQL Managed Instance in a dedicated subnet. To meet corporate policy you attach a Network Security Group (NSG) to the subnet and delete the default Allow Internet Outbound rule, effectively blocking all outbound Internet traffic. After the change, the managed instance remains stuck in the Creating state and eventually fails to provision. You must keep the Internet block in place but still allow the managed instance to deploy and operate. Which single NSG rule should you add?

  • Allow outbound UDP 1194 to the service tag GatewayManager

  • Allow outbound TCP 443 to the service tag Internet

  • Allow outbound TCP 1443 to the service tag VirtualNetwork

  • Allow outbound TCP 443 to the service tag SqlManagement

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot