Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium
A network administrator is designing an Azure Virtual Network (VNet) for a new application. The VNet will contain several subnets, and each subnet needs to have its own dedicated Network Security Group (NSG) to control traffic flow. The administrator wants to ensure that a specific NSG is always applied to a particular subnet, even if new VMs are added or removed from that subnet. How should the NSG be associated?
- AUse Azure Policy to enforce NSG association at the VM level.
- BAssociate the NSG to each individual Network Interface Card (NIC) of the VMs in the subnet.
- CCreate an Application Security Group (ASG) and associate it with the NSG.
- DAssociate the NSG directly to the subnet.
Show answer & explanationAnswer & explanation
Correct answer: D. Associate the NSG directly to the subnet.
Associating an NSG directly to a subnet ensures that all resources within that subnet, including new or existing VMs, automatically inherit and are subject to the rules defined in that NSG. This provides consistent network security for the entire subnet.
Why the other options are wrong
- A. Azure Policy can enforce NSG association, but the fundamental method of association is still at the subnet or NIC level. Option B is the direct and primary method of achieving the goal.
- B. Associating to NICs provides granular control but requires manual management for each VM, which is not ideal for ensuring a specific NSG is 'always applied' to the subnet.
- C. ASGs are used to group VMs and define NSG rules based on application workload, but they don't directly associate an NSG to a subnet.
NSG Subnet Association
Associating a Network Security Group (NSG) to a subnet applies its security rules to all resources within that subnet, providing a consistent and scalable approach to network traffic filtering.
- NSGs can be associated with subnets or NICs.
- Subnet association applies rules to all resources in the subnet.
- NIC association provides granular, per-VM control.
- Rules are evaluated first at the subnet level, then at the NIC level.
Memory trick: Subnet for broad, NIC for fine, both for full control.