Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company has 75 virtual networks spread across three Azure subscriptions. You must immediately block all outbound traffic to two public IP addresses that have been reported as command-and-control endpoints, while avoiding per-NSG changes. What should you do?
Add a user-defined route with next hop set to None for the two IP addresses in each subnet of every virtual network.
Associate the affected virtual machines with a new application security group and add a deny outbound rule to existing NSGs that references this group.
Create a security admin rule collection in Azure Virtual Network Manager, attach it to a network group that contains all virtual networks, and add a deny outbound rule for the two IP addresses.
Deploy a centralized Azure Firewall in a hub virtual network and add an outbound application rule that denies connections to the two IP addresses.
Security admin rules in Azure Virtual Network Manager are evaluated before subnet-level NSG rules and apply to every network that belongs to the selected network group, regardless of subscription. Creating a deny, outbound security admin rule that targets the malicious IP addresses meets the requirement in a single configuration step and does not require modifying individual NSGs. User-defined routes or Azure Firewall would need additional routing changes in every virtual network, and NSG rules referencing an application security group would still have to be added to each NSG individually.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Virtual Network Manager?
Open an interactive chat with Bash
What are security admin rule collections?
Open an interactive chat with Bash
How do security admin rules differ from NSG rules?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .