Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingEasy

A security administrator needs to restrict inbound network traffic to a specific Azure Virtual Machine. The VM should only accept RDP (Remote Desktop Protocol) connections on port 3389 from a predefined set of IP addresses. Which Azure networking component should be configured to achieve this?

  1. AAzure Virtual Network Gateway
  2. BAzure Network Security Group (NSG)
  3. CAzure Private Link
  4. DAzure Front Door
Show answer & explanation

Correct answer: B. Azure Network Security Group (NSG)

An Azure Network Security Group (NSG) allows you to filter network traffic to and from Azure resources in an Azure Virtual Network. You can define rules to permit or deny traffic based on source/destination IP address, port, and protocol.

Why the other options are wrong

  • A. Azure Virtual Network Gateway connects Azure Virtual Networks to on-premises networks or other VNets, not for filtering specific VM traffic.
  • C. Azure Private Link provides private connectivity to Azure services, not for filtering traffic to a VM.
  • D. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, not for VM-level traffic filtering.

Network Security Group (NSG)

A security feature that filters network traffic to and from Azure resources within an Azure Virtual Network.

  • Contains security rules that allow or deny inbound/outbound traffic.
  • Rules are based on source/destination IP, port, and protocol.
  • Can be associated with subnets or individual network interfaces.

Memory trick: NSG is the 'traffic cop' for your 'VMs and subnets'.

More Describe Azure identity, security, and networking questions