AZ-700 exam dumps

AZ-700 practice question 278 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 278

Single answer

You are an Azure networking engineer for a global organization that spans multiple Azure subscriptions. The company wants to implement a consistent network security posture across all subscriptions by blocking inbound SSH from the internet, except from a designated on-premises management subnet. You have been asked to implement these security rules at scale using Azure Virtual Network Manager. Which approach should you use to achieve this requirement with minimal administrative overhead?

  1. A

    Create a Security Admin Configuration in Azure Virtual Network Manager and apply it to a group of virtual networks

  2. B

    Manually deploy individual network security groups (NSGs) with custom SSH rules in each virtual network

  3. C

    Use Azure Policy to automatically provision NSGs for each subscription preventing inbound SSH from unauthorized sources

  4. D

    Implement a user-defined route (UDR) that redirects all inbound SSH traffic to a standalone firewall

Show answer and explanation

Correct answer: A

Explanation

Azure Virtual Network Manager simplifies centralized security configuration by defining and applying Security Admin Configurations that create enforcement rules across multiple virtual networks. This approach is recommended for scenarios where organizations need a consistent security posture for inbound traffic while reducing manual effort. Refer to the Microsoft documentation on Azure Virtual Network Manager (https://learn.microsoft.com/azure/virtual-network-manager/overview) for detailed guidance on implementing network security at scale.

  • A. Correct.

    Option 1 is correct. With Azure Virtual Network Manager, you can create a Security Admin Configuration that defines a set of inbound rules to block SSH from untrusted sources, allowing only the designated management subnet. Once you apply this configuration to a group of virtually connected networks, it enforces the policy across all selected virtual networks in one step.

  • B. Incorrect.

    Option 2 is incorrect. Although NSGs can block SSH traffic, deploying and maintaining these settings manually in each virtual network is time-consuming and prone to configuration drift. Azure Virtual Network Manager provides a centralized way to enforce consistent rules.

  • C. Incorrect.

    Option 3 is incorrect. While Azure Policy can help audit or deploy resources, it's not primarily designed to replace or centrally manage all network security configurations across multiple virtual networks. Azure Virtual Network Manager is the dedicated solution for centralized security rule enforcement within virtual networks.

  • D. Incorrect.

    Option 4 is incorrect. A user-defined route (UDR) can redirect traffic, but it does not inherently block SSH from unauthorized sources on its own. You would still require additional firewall or security rules to enforce the desired security posture.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam