Microsoft Security, Compliance, and Identity Fundamentals SC-900 Practice Question
Your company hosts a web application on Azure virtual machines inside a single virtual network. You must restrict inbound traffic to TCP port 443 from the corporate IP range and deny all outbound traffic to the internet except HTTP/HTTPS. Which Azure service should you use to enforce these rules at the subnet or NIC level?
Azure Firewall
Network security group
Web Application Firewall on Azure Application Gateway
Network security groups (NSGs) provide stateful packet filtering based on source and destination IP address, port, and protocol. They can be associated with individual subnets or individual network interfaces, making them ideal for controlling inbound and outbound traffic to specific workloads. Azure DDoS Protection focuses on large-scale volumetric attacks but does not let you author custom port and protocol rules. Azure Firewall offers centralized, stateful filtering at the virtual-network perimeter, not directly on subnets or NICs. Web Application Firewall protects HTTP/S traffic at the application layer but cannot create general network-level allow/deny rules for other protocols.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Network Security Group (NSG) in Azure?
Open an interactive chat with Bash
How does a Network Security Group differ from Azure Firewall?
Open an interactive chat with Bash
What types of scenarios are best suited for using a Network Security Group?
Open an interactive chat with Bash
Microsoft Security, Compliance, and Identity Fundamentals SC-900
Describe the capabilities of Microsoft security solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .