Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your Azure VNet has WebSubnet (web-tier VM scale set) and AppSubnet (application VMs). Requirements:

  1. Allow Internet → web tier on TCP 443.
  2. Allow web tier → app tier on TCP 8080.
  3. Block any traffic initiated from AppSubnet to the Internet or WebSubnet. You must minimise NSG rules and ensure policies automatically cover new scale-out instances. What should you configure?
  • Use Azure Virtual Network Manager to create security admin rule collections that allow and deny the required traffic.

  • Associate both subnets with a single Network Security Group that contains individual CIDR-based allow and deny rules for each subnet.

  • Create two Application Security Groups (one for the web tier and one for the app tier) and reference them in the required NSG rules.

  • Deploy an Azure Firewall in a dedicated subnet and configure user-defined routes so all traffic is forced through the firewall.

Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot