Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company runs 40 VMs in two subnets, WebSubnet and AppSubnet, inside one virtual network. Every NIC in WebSubnet belongs to an Application Security Group (ASG) named WebTier. A Network Security Group (NSG) called PerimeterNSG is already associated with WebSubnet. You need to let Internet clients access only the WebTier VMs on TCP 443 and expose nothing else. Which NSG configuration achieves this with minimal administration?
Associate PerimeterNSG with both subnets and add an inbound rule: Source = Internet, Destination = Any, Port = 443, Allow, plus an outbound allow rule for the same port.
Create an inbound rule: Source = Internet, Destination = VirtualNetwork, Port = 443, Allow; then associate PerimeterNSG with both WebSubnet and AppSubnet.
Create one inbound rule in PerimeterNSG: Priority 100, Source = Internet (service tag), Destination = WebTier (ASG), Port = 443, Protocol = TCP, Action = Allow; rely on default rules for all other traffic.
Create an inbound rule in PerimeterNSG: Source = Internet, Destination = WebSubnet, Port = 443, Allow; and an outbound rule that denies all traffic to the virtual network.
Referencing the ASG as the destination lets the NSG rule target only those NICs that belong to WebTier, even though the NSG is attached to the entire subnet. A single inbound allow rule from the Internet service tag to the WebTier ASG on port 443 satisfies the requirement. All other unsolicited traffic continues to be blocked by the NSG's default deny-all inbound rule, so no additional rules are necessary. The other options either expose the whole subnet, require extra rules, or associate the NSG where it is not needed, increasing risk or administrative overhead.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Application Security Group (ASG) in Azure?
Open an interactive chat with Bash
What is the purpose of default rules in a Network Security Group (NSG)?
Open an interactive chat with Bash
What is the Internet service tag in Azure NSG?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .