Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium
A company has several virtual machines (VMs) deployed in an Azure Virtual Network. They want to control inbound and outbound network traffic to these VMs based on IP addresses, ports, and protocols. Which Azure networking component should they use to achieve this granular control at the subnet or VM network interface level?
- AAzure Application Gateway
- BAzure Public IP Address
- CNetwork Security Group (NSG)
- DAzure Load Balancer
Show answer & explanationAnswer & explanation
Correct answer: C. Network Security Group (NSG)
A Network Security Group (NSG) allows you to filter network traffic to and from Azure resources in an Azure Virtual Network. An NSG contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.
Why the other options are wrong
- A. Azure Application Gateway is a web traffic load balancer that includes a Web Application Firewall (WAF).
- B. Azure Public IP Address provides internet connectivity to Azure resources.
- D. Azure Load Balancer distributes traffic, not filters it based on rules.
Network Security Group (NSG)
A Network Security Group (NSG) is an Azure networking component that contains security rules to filter network traffic to and from Azure resources.
- Filters traffic based on IP, port, protocol
- Can be associated with subnets or individual NICs
- Rules are processed by priority
- Default rules allow all outbound, deny all inbound from internet
Memory trick: NSG is the bouncer at the door, checking IDs and deciding who gets in or out.