You plan to deploy several Azure virtual machines. You need to control the ports that devices on the Internet can use to access the virtual machines. What should you use?
A network security group (NSG) contains a list of security rules that allow or deny network traffic to resources connected to Azure Virtual Networks (VNet). NSGs can be associated to subnets, individual VMs (classic), or individual network interfaces (NIC) attached to VMs (Resource Manager)
A is the correct answer.
A is the answer.
https://learn.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview
You can use an Azure network security group to filter network traffic between Azure resources in an Azure virtual network. A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources. For each rule, you can specify source and destination, port, and protocol.
A network security group (NSG) is a feature in Azure that allows you to control inbound and outbound network traffic to and from Azure resources. You can create rules that specify the ports and protocols that can be used to access your virtual machines, and you can apply the NSG to individual virtual machines or to a subnet in a virtual network. With NSG, you can create inbound and outbound security rules, allow or deny traffic based on source and destination IP address, port, and protocol.
Azure Active Directory (Azure AD) is a service
You can attach a network security group to a virtual network and/or individual subnets within the virtual network. - It's a wrong statement. You can assign NSG only to subnet and NIC in a virtual machine.
You can associate zero, or one, network security group to each virtual network subnet and network interface in a virtual machine. The same network security group can be associated to as many subnets and network interfaces as you choose.
https://docs.microsoft.com/en-us/azure/virtual-network/network-security-group-how-it-works
"You can attach a network security group to a virtual network and/or individual subnets within the virtual network." Is wrong. A previous questions states that you cannot attach a nsg to a virtual network. Only subnets and NICS
Azure Firewall is for filtering traffic from outside Azure world , that is , internet . NSG is for filtering traffic from within Azure resources ...Option of Azure Firewall is not present
Azure Firewall is a stateful (and expensive) option for controlling traffic.
NSGs are like access contorl lists - it does the job. Source and destination for NSG can be outside of Azure.
A network security group (NSG) enables you to filter network traffic to and from Azure resources within an Azure Virtual Network. You can think of network security groups like an internal firewall. An NSG can contain multiple inbound and outbound security rules that enable you to filter traffic to and from resources by source and destination IP address, port, and protocol.
This section is not available anymore. Please use the main Exam Page.AZ-900 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Sandy4912
Highly Voted 3 years, 10 months agovaisat
Highly Voted 4 years, 3 months agomytapun
3 years, 5 months agoSAFM
Most Recent 7 months agozellck
1 year, 3 months agozellck
1 year, 3 months agothelukas1997
1 year, 5 months agoTom34
1 year, 11 months agoHassan110
2 years, 2 months agoSubhrajit
2 years, 3 months agoSarahxx
2 years, 9 months agoAzureDrew
2 years, 10 months agotaoj
2 years, 11 months agosamuelgarcia
2 years, 11 months agoGeorgess
2 years, 6 months agopedrolindeza
2 years, 11 months agoGerardo1971
3 years agojashish79
3 years, 2 months agoDartTrapdoor
2 years, 10 months agopanal
3 years, 2 months agoetoto
3 years, 4 months agoPrates_BR
3 years, 4 months ago