AZ-104 exam dumps

AZ-104 practice question 216 of 289

Microsoft Certified: Azure Administrator Associate. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-104 Question 216

Select 2

You are an Azure Administrator for Contoso. The company uses an ExpressRoute connection to reach an Azure Virtual Network (VNet) named 'ProdVNet'. You need to ensure that only traffic from your on-premises IP ranges can access a set of Windows servers in the 'ProdSubnet' over port 443, and all other inbound connections are blocked. Which two actions should you perform to configure secure access to the 'ProdSubnet'?

  1. A

    Create and associate a Network Security Group (NSG) with an inbound allow rule for port 443 from your on-premises IP ranges.

  2. B

    Configure a user-defined route to forward inbound port 443 traffic from on-premises to a gateway subnet for inspection.

  3. C

    Enable a service endpoint for port 443 on 'ProdSubnet' to restrict inbound connections to on-premises sources only.

  4. D

    Rely on the built-in default NSG rule that denies all inbound traffic not previously allowed.

Show answer and explanation

Correct answers: A, D

Explanation

To secure access and allow only traffic from specific on-premises IP ranges, you must create an NSG with the appropriate allow rule while relying on the existing default deny rule to block everything else. User-defined routes and service endpoints do not meet the requirement to restrict inbound traffic from external sources in this scenario.

  • A. Correct.

    This is a valid method: creating an NSG, associating it with the subnet, and adding an inbound allow rule scoped to your on-premises IP ranges on port 443 ensures only approved traffic is permitted.

  • B. Incorrect.

    A user-defined route does not by itself restrict inbound access; it merely changes routing paths. It does not fulfill the requirement of allowing only specific IP ranges over port 443.

  • C. Incorrect.

    Service endpoints are used to secure traffic to Azure PaaS services within a VNet, not to restrict general inbound traffic from on-premises sources.

  • D. Correct.

    Azure NSGs have a default deny rule at the lowest priority. If no other rule explicitly allows traffic, it is blocked by default, effectively ensuring all unauthorized inbound traffic is denied.

Timed practice exam

Take a AZ-104 practice test under exam conditions

60 questions in 60 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam