Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an Azure virtual network with virtual machines that autoscale across Web, API, and Database tiers. You must ensure only Web tier VMs can initiate HTTPS traffic to API tier VMs while minimizing NSG rules and avoiding changes when instances are added or removed. Which feature should you use?
Deploy an Azure Firewall instance and write network rules for the traffic.
Assign the VMs to Application Security Groups and create a single NSG rule that uses the ASGs as source and destination.
Create user-defined routes and associate them with a route table.
Enable service endpoints for Microsoft.Web on both subnets.
Application Security Groups (ASGs) let you logically group NICs that belong to the same workload tier. When you reference ASGs as the source and destination in a single NSG rule, the rule automatically applies to every VM whose NIC is added to, or removed from, the group. This eliminates the need to maintain individual IP-based rules as instances scale. User-defined routes, service endpoints, or Azure Firewall rules would not reduce NSG rule count for intra-VNet traffic and would still require ongoing maintenance or additional cost.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Application Security Groups (ASGs) in Azure?
Open an interactive chat with Bash
How do ASGs minimize the number of NSG rules?
Open an interactive chat with Bash
Why are Application Security Groups better suited for autoscaling scenarios?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .