Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage a three-tier solution in a single Azure virtual network. Ten VMs in the app subnet must reach ten VMs in the db subnet over TCP 1433. One NSG is associated with both subnets, and VM NICs receive new private IPs whenever the solution scales. You need the fewest, maintenance-free NSG rules that allow only the application tier to initiate the SQL traffic. What should you do?
Enable a Microsoft.Sql service endpoint on the app subnet and delete all existing NSG rules that block port 1433.
Deploy Azure Firewall, force-tunnel all subnet traffic through it, and create a firewall rule that permits TCP 1433 from the app subnet to the db subnet.
Create an NSG rule that allows TCP 1433 from the current private IP addresses of the application VMs to the database subnet.
Create two Application Security Groups, add the application VMs to one and the database VMs to the other, and add a single NSG rule that allows TCP 1433 from the application ASG to the database ASG.
Application Security Groups (ASGs) let you group NICs logically and reference those groups as the source and destination in a single NSG rule. Because membership is evaluated by NIC association at runtime, rules do not change when VMs scale or receive new IP addresses. Creating one ASG for the application VMs and another for the database VMs, then adding a single NSG rule that allows TCP 1433 from the application ASG to the database ASG, meets the requirement with minimal ongoing maintenance. The other options rely on static IP addresses, grant overly broad access, or add unnecessary infrastructure.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Application Security Groups (ASGs) in Azure?
Open an interactive chat with Bash
How do ASGs ensure maintenance-free network security in Azure?
Open an interactive chat with Bash
Why is using ASGs better than relying on static IP addresses in Azure NSGs?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .