Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium

A security engineer is tasked with securing an Azure Virtual Network (VNet) that hosts several critical backend services. These services should only be accessible from a specific set of Azure Virtual Machines (VMs) within the same VNet and from a highly restricted on-premises network. All other inbound and outbound traffic to these backend services must be blocked by default. Which Azure networking security feature provides the most granular control at the subnet or network interface level to enforce these traffic flow rules?

  1. ANetwork Security Groups (NSGs)
  2. BAzure DDoS Protection Standard
  3. CAzure Private Link
  4. DAzure Firewall
Show answer & explanation

Correct answer: A. Network Security Groups (NSGs)

Network Security Groups (NSGs) provide granular control over network traffic to and from Azure resources within a VNet at the subnet or individual network interface level. They allow defining inbound and outbound security rules based on source/destination IP address, port, and protocol, directly addressing the requirement for specific VM and on-premises access while blocking all other traffic.

Why the other options are wrong

  • B. Azure DDoS Protection Standard protects against volumetric attacks but does not control specific traffic flows or access rules.
  • C. Azure Private Link provides private connectivity to Azure PaaS services or customer-owned services, not for controlling traffic between VMs and subnets within a VNet or from on-premises.
  • D. Azure Firewall provides centralized, VNet-wide network security, but for granular control at the subnet/NIC level within a VNet, NSGs are more appropriate and often used in conjunction.

Network Security Groups (NSGs)

Network Security Groups (NSGs) filter network traffic to and from Azure resources in an Azure Virtual Network (VNet) based on IP address, port, and protocol.

  • Applied to subnets or individual network interfaces (NICs).
  • Contain security rules that allow or deny inbound/outbound traffic.
  • Rules are processed by priority number (lower number = higher priority).
  • Provide granular network access control within a VNet.

Memory trick: For network traffic, NSGs are the gates at the subnet's edge.

More Implement platform protection questions