exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 3 question 18 discussion

Actual exam question from Microsoft's AZ-500
Question #: 18
Topic #: 3
[All AZ-500 Questions]

SIMULATION -
You need to ensure that connections from the Internet to VNET1\subnet0 are allowed only over TCP port 7777. The solution must use only currently deployed resources.
To complete this task, sign in to the Azure portal.

Show Suggested Answer Hide Answer
Suggested Answer: See the explanation below.
You need to configure the Network Security Group that is associated with subnet0.
1. In the Azure portal, type Virtual Networks in the search box, select Virtual Networks from the search results then select VNET1. Alternatively, browse to
Virtual Networks in the left navigation pane.
2. In the properties of VNET1, click on Subnets. This will display the subnets in VNET1 and the Network Security Group associated to each subnet. Note the name of the Network Security Group associated to Subnet0.
3. Type Network Security Groups into the search box and select the Network Security Group associated with Subnet0.
4. In the properties of the Network Security Group, click on Inbound Security Rules.
5. Click the Add button to add a new rule.
6. In the Source field, select Service Tag.
7. In the Source Service Tag field, select Internet.
8. Leave the Source port ranges and Destination field as the default values (* and All).
9. In the Destination port ranges field, enter 7777.
10.Change the Protocol to TCP.
11.Leave the Action option as Allow.
12.Change the Priority to 100.
13.Change the Name from the default Port_8080 to something more descriptive such as Allow_TCP_7777_from_Internet. The name cannot contain spaces.
14.Click the Add button to save the new rule.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mic8888
Highly Voted 3 years ago
All services or type 'network security groups' on the search bar > click your target NSG > on Settings, click 'Inbound security rules' > click + Add > Source: service tag, destination port: 7777, Protocol: TCP, Priority:100, Name:<provide name>, and leave the rest as defaults > click Add
upvoted 13 times
...
CarlosBarrero
Highly Voted 4 years, 2 months ago
the answer is correct
upvoted 8 times
...
Viggy1212
Most Recent 7 months ago
Question says Traffic should be allowed from Internet to subnet0. Usage of Destination "Any" will allow traffic to all subnet which is little over the requirement. Hence only CIDR notation of subnet2 only should be mentioned in Destination of Inbound Security rule.
upvoted 1 times
...
mrt007
1 year, 1 month ago
Sign in to the Azure portal. In the left-hand menu, click on “All services”. In the “All services” box, type “Network Security Group”. Click on the “Network Security Groups” item in the search results. In the “Network security groups” window, find and click on the network security group that is associated with VNET1\subnet0. In the settings menu of the selected network security group, click on “Inbound security rules”. Click on the “+ Add” button to create a new inbound security rule. In the “Add inbound security rule” window, fill in the following details: Source: Any Source port ranges: * Destination: Any Destination port ranges: 7777 Protocol: TCP Action: Allow Priority: Choose a value less than 65000. Lower numbers have higher priorities. Name: Choose a name for this rule. Click on the “Add” button to create the rule.
upvoted 3 times
...
fireb
1 year, 7 months ago
Answer provided is correct.
upvoted 1 times
...
F117A_Stealth
2 years, 5 months ago
the answer is correct
upvoted 1 times
...
Patchfox
3 years, 4 months ago
Correct. All other default rules already block traffic from outside the vnet.
upvoted 1 times
...
orallony
3 years, 7 months ago
# IN EXAM - 29/9/2021 - Pass!
upvoted 3 times
OldJan
3 years, 5 months ago
So the simulation questions are back?
upvoted 1 times
...
...
JAGUDERO
4 years, 1 month ago
something is missing, This does not restrict the currently deployed resources
upvoted 1 times
eroms
3 years, 11 months ago
Maybe restrict destination field to the Subnet of the connected Vnet1.
upvoted 1 times
...
Ed2learn
3 years, 11 months ago
Think you misread the question. You do not need to restrict existing resources - you cannot create new resources. In other words you must add rule to existing NSG
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago