Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your Azure virtual network includes two subnets that host several Linux VMs acting as web servers. The number of web servers changes frequently as the solution scales. You need to allow inbound TCP ports 80 and 443 only to the web servers while keeping security-rule maintenance effort to a minimum. What should you configure?
Associate the web-server network interfaces with an Application Security Group and reference that ASG in a single NSG rule allowing TCP 80 and 443.
In the NSG, add inbound rules that allow TCP 80 and 443 from the VirtualNetwork service tag.
Create a user-defined route that sends 0.0.0.0/0 traffic to a network virtual appliance that filters ports 80 and 443.
Deploy Azure Firewall and configure individual DNAT rules for ports 80 and 443 to each web server.
An Application Security Group (ASG) lets you assign the network interfaces of the web-server VMs to a logical group such as "WebServers". You can then reference that ASG in a single inbound Network Security Group (NSG) rule that permits TCP 80 and 443. When new web servers are added or removed, you only add or remove their NICs from the ASG; the NSG rule itself never has to change. User-defined routes, Azure Firewall DNAT, or NSG rules that rely on the VirtualNetwork service tag either do not target only the web servers or require continual rule updates, so they do not satisfy the requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Application Security Group (ASG) in Azure?
Open an interactive chat with Bash
How does an NSG (Network Security Group) work in Azure?
Open an interactive chat with Bash
What are the benefits of using ASGs with NSGs in Azure?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .