AZ-500 exam dumps

AZ-500 practice question 45 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 45

Select 2

Your company has deployed a hub-and-spoke virtual network architecture in Azure for a mission-critical application. The application VMs reside in a spoke subnet and must only allow inbound network traffic from specific management IP addresses while permitting required communication from the hub. All other inbound internet traffic should be blocked. You need to plan and implement a security solution that meets these requirements while ensuring minimal configuration drift. Which two options should you include in your plan?

  1. A

    A. Apply a Network Security Group (NSG) at the subnet level of the spoke to allow inbound traffic only from the specified management IP addresses and block all other inbound internet traffic.

  2. B

    B. Disable the default subnet-level NSG and rely solely on individual NSGs at each VM’s network interface.

  3. C

    C. Configure and deploy Azure Firewall in the hub network, creating firewall rules that only allow inbound connections from the management IP addresses to the spoke.

  4. D

    D. Enable forced tunneling on the spoke subnet to route all traffic to an on-premises firewall for inspection.

  5. E

    E. Remove all custom routes from the spoke subnet to rely exclusively on Microsoft default routes.

Show answer and explanation

Correct answers: A, C

Explanation

To secure inbound traffic to the spoke from only specific IP addresses, you should use a subnet-level NSG (Option A) with explicit allow and deny rules, as recommended by Azure best practices. Additionally, deploying Azure Firewall in the hub (Option C) provides a scalable approach to control and monitor traffic to all spoke subnets. These two measures together fulfill the scenario’s strict inbound requirements while maintaining a centralized, manageable security solution. Refer to Microsoft documentation on 'Security best practices for IaaS workloads in Azure' and 'Hub-spoke network architecture in Azure' for more details.

  • A. Correct.

    A. Correct. Applying an NSG at the subnet level is a best practice for managing inbound and outbound traffic control on all VMs in that subnet. You can create rules allowing traffic only from specific management IP addresses, ensuring that other unwanted traffic from the internet is blocked.

  • B. Incorrect.

    B. Incorrect. While you can place NSGs on individual network interfaces, administering numerous VMs this way is error-prone and can lead to configuration drift. Subnet-level NSGs help maintain consistency across all VMs in the spoke subnet.

  • C. Correct.

    C. Correct. An Azure Firewall in the hub can centrally manage and monitor traffic to multiple spoke subnets. You can define firewall rules that explicitly permit inbound connections only from authorized management IPs, fulfilling the security requirement.

  • D. Incorrect.

    D. Incorrect. Forced tunneling routes all internet-bound traffic on the spoke to on-premises, but it doesn’t in itself restrict specific inbound IP ranges. You would still require rules at NSGs or Azure Firewall to enforce the inbound restrictions from the management IP addresses.

  • E. Incorrect.

    E. Incorrect. Removing custom routes and relying solely on default routes will not address the requirement to block unwanted inbound traffic from the internet. Proper firewall or NSG rules are still needed for that.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam