ISC2 Certified Cloud Security Professional (CCSP) Practice Question
In an Azure virtual network, a security team must ensure that production application VMs in the web subnet accept HTTP and HTTPS traffic from the Internet, block all other inbound connections, and allow SSH only from the corporate office's public IP address. The control must provide stateful packet filtering at layer 3/4, be applied directly to the subnet, and introduce no additional per-hour service cost. Which Azure network security control should be implemented?
Attach an Azure Network Security Group to the web subnet and create rules permitting TCP 80/443 from any source and TCP 22 only from the corporate office IP.
Provision Azure Bastion and configure its access policies to allow only HTTP, HTTPS, and SSH from approved sources.
Implement an Azure Application Gateway with a Web Application Firewall (WAF) and limit source IPs in the listener configuration.
Deploy Azure Firewall in the virtual network and define network and application rules to control HTTP, HTTPS, and SSH access.
Azure Network Security Groups (NSGs) are designed to perform stateful layer 3/4 packet filtering and can be associated with individual subnets or network interfaces. Administrators create inbound and outbound security rules that explicitly allow or deny traffic such as HTTP (TCP 80), HTTPS (TCP 443), and SSH (TCP 22) from specified source IP addresses. NSGs are a built-in capability of the Azure virtual network fabric and do not incur extra hourly charges.
Azure Firewall also provides stateful filtering but is a separate managed service that incurs additional costs and is typically used for centralized, large-scale filtering across multiple subnets. Azure Application Gateway with WAF works at layer 7 as a reverse proxy and does not natively control SSH or general inbound port access to VMs. Azure Bastion offers secure browser-based RDP/SSH without public IPs but is not intended to enforce granular port-based filtering for other traffic types. Therefore, configuring an NSG on the web subnet most directly meets all stated requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Azure Network Security Group (NSG)?
Open an interactive chat with Bash
What is the difference between Azure Firewall and NSGs?
Open an interactive chat with Bash
Why is Azure Application Gateway with WAF not suitable in this case?
Open an interactive chat with Bash
What is an Azure Network Security Group (NSG)?
Open an interactive chat with Bash
What does stateful packet filtering mean in Azure NSGs?
Open an interactive chat with Bash
Why is Azure Firewall not suitable for this scenario?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .