Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

A company is designing an Azure environment and needs to restrict network traffic between different subnets within a Virtual Network. They want to define granular rules based on IP addresses, ports, and protocols to control inbound and outbound access for virtual machines. Which Azure security component should they use?

  1. AAzure Application Gateway
  2. BAzure Firewall
  3. CAzure DDoS Protection Standard
  4. DNetwork Security Group (NSG)
Show answer & explanation

Correct answer: D. Network Security Group (NSG)

Network Security Groups (NSGs) allow you to filter network traffic to and from Azure resources in an Azure Virtual Network. An NSG contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.

Why the other options are wrong

  • A. Azure Application Gateway is a web traffic load balancer, not designed for granular subnet-level traffic filtering.
  • B. Azure Firewall provides stateful firewall as a service for all resources, often used for centralized perimeter security.
  • C. Azure DDoS Protection Standard protects against distributed denial of service attacks, not for internal traffic filtering.

Network Security Group (NSG)

A security component that filters network traffic to and from Azure resources in an Azure Virtual Network.

  • Contains security rules that allow or deny inbound/outbound traffic.
  • Rules are based on source/destination IP, port, and protocol.
  • Can be associated with subnets or individual network interfaces (NICs).

Memory trick: NSG is the traffic cop for your virtual subnet.

More Describe Azure identity, security, and networking questions