Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A security engineer is designing a secure network architecture for a multi-tier application deployed in an Azure Virtual Network. The application consists of a web tier, an application tier, and a database tier, each residing in its own subnet. The requirement is to restrict traffic flow between these subnets, allowing only necessary communication (e.g., web server to app server, app server to database). Which Azure networking resource should be used to enforce these granular subnet-level traffic filtering rules?

  1. AAzure Load Balancer
  2. BUser-Defined Routes (UDRs)
  3. CNetwork Security Groups (NSGs)
  4. DAzure Firewall
Show answer & explanation

Correct answer: C. Network Security Groups (NSGs)

Network Security Groups (NSGs) are used to filter network traffic to and from Azure resources in an Azure Virtual Network. They allow you to define inbound and outbound security rules that control traffic at the subnet or individual VM network interface level, making them ideal for granular subnet-level filtering.

Why the other options are wrong

  • A. Azure Load Balancer distributes incoming network traffic to multiple backend resources, not for security filtering between subnets.
  • B. UDRs control traffic routing paths, not traffic filtering or access control.
  • D. Azure Firewall provides centralized, stateful firewall capabilities for VNets, but NSGs are more granular for direct subnet-to-subnet filtering.

Network Security Groups (NSGs)

Network Security Groups (NSGs) are an Azure networking feature that allows you to filter network traffic to and from Azure resources in an Azure Virtual Network, using security rules.

  • Filter traffic at Layer 4 (TCP/UDP ports).
  • Can be associated with subnets or individual network interfaces.
  • Rules are evaluated by priority, with lower numbers having higher priority.
  • Default rules exist to allow/deny certain traffic.

Memory trick: NSG: The security guard for your subnet's doorstep.

More Implement platform protection questions