Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium

A security engineer is designing a secure network architecture for a multi-tier application in Azure. The application consists of a web tier, an application tier, and a database tier, each residing in its own subnet within an Azure Virtual Network. The requirement is to restrict network traffic flow between these subnets to only the necessary ports and protocols (e.g., web tier to app tier on port 8080, app tier to database tier on port 1433). Which Azure network security control should be implemented at the subnet level to enforce these granular traffic restrictions?

  1. AApplication Security Groups (ASGs)
  2. BAzure Firewall
  3. CNetwork Security Groups (NSGs)
  4. DAzure DDoS Protection Standard
Show answer & explanation

Correct answer: C. Network Security Groups (NSGs)

Network Security Groups (NSGs) allow you to filter network traffic to and from Azure resources in an Azure Virtual Network. You can define security rules that permit or deny traffic based on source IP address, destination IP address, source port, destination port, and protocol, making them ideal for granular control at the subnet or NIC level.

Why the other options are wrong

  • A. Application Security Groups (ASGs) simplify NSG rule management by grouping VMs, but the enforcement mechanism itself is still NSGs.
  • B. Azure Firewall is a centralized, stateful firewall, typically used for perimeter protection, not granular inter-subnet filtering within a VNet where NSGs are more efficient.
  • D. Azure DDoS Protection Standard protects against denial-of-service attacks, which is unrelated to inter-subnet traffic filtering.

Network Security Groups (NSGs)

Azure NSGs filter network traffic to and from Azure resources in an Azure Virtual Network. An NSG contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.

  • Operate at Layer 3/4.
  • Can be associated with subnets or network interfaces.
  • Rules based on source/destination IP, port, and protocol.

Memory trick: NSGs are the traffic controllers for your subnets.

More Implement platform protection questions