Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You deploy an internal load balancer (ILB) App Service Environment (ASE) v3 in the delegated subnet Prod-Ase-Subnet of a virtual network named Prod-VNet.
The ASE hosts several internal line-of-business web apps that must be reachable only from your on-premises network over an existing ExpressRoute private peering.
You create a Network Security Group (NSG) and associate it with Prod-Ase-Subnet.
You must meet the following requirements:

  • Allow HTTPS traffic (TCP 443) from the on-premises address range 10.30.0.0/16 to the web apps.
  • Keep the minimum set of inbound rules that are required for the Azure App Service platform to manage the ASE.

Which additional inbound NSG source should you allow to make sure the ASE continues to be managed by the App Service platform while still blocking unsolicited Internet traffic?

  • Source Any on port 454

  • Service tag AzureLoadBalancer on ports 80 and 443

  • Source VirtualNetwork on all ports

  • Service tag AppServiceManagement on the required management ports

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot