Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingEasy
A pilot project involves deploying a web application with a single Azure Virtual Machine (VM) in a new Azure Virtual Network (VNet). The application needs to be accessible from the internet over HTTPS (port 443). Which is the MINIMUM number of Network Security Groups (NSGs) that must be configured to secure this VM, while allowing the required inbound traffic?
- A2
- B1
- C3
- D0
Show answer & explanationAnswer & explanation
Correct answer: B. 1
A single NSG can be associated with either the network interface (NIC) of the VM or the subnet where the VM resides. This single NSG can contain an inbound rule allowing HTTPS (port 443) traffic from the internet, fulfilling the requirement.
Why the other options are wrong
- A. While you can apply NSGs at both the NIC and subnet level, it's not the minimum required. One NSG at either level is sufficient for this basic scenario.
- C. Three NSGs are unnecessary for a single VM with basic inbound HTTPS access.
- D. Without any NSG, the VM would be fully exposed (if a public IP is attached) or completely inaccessible, neither of which meets the security requirement.
NSG Association Scope
Network Security Groups can be associated with either a subnet or an individual network interface (NIC) of a VM, or both.
- Rules are processed at both levels if two NSGs are applied.
- Subnet NSG rules are processed first for inbound traffic, then NIC NSG rules.
- NIC NSG rules are processed first for outbound traffic, then Subnet NSG rules.
Memory trick: One NSG: Your VM's single security guard.