exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 5 question 54 discussion

Actual exam question from Microsoft's AZ-104
Question #: 54
Topic #: 5
[All AZ-104 Questions]

You have an Azure virtual machine named VM1.
The network interface for VM1 is configured as shown in the exhibit. (Click the Exhibit tab.)

You deploy a web server on VM1, and then create a secure website that is accessible by using the HTTPS protocol. VM1 is used as a web server only.
You need to ensure that users can connect to the website from the Internet.
What should you do?

  • A. Modify the protocol of Rule4
  • B. Delete Rule1
  • C. For Rule5, change the Action to Allow and change the priority to 401
  • D. Create a new inbound rule that allows TCP protocol 443 and configure the rule to have a priority of 501.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mlantonis
Highly Voted 3 years, 11 months ago
Correct Answer: C HTTPS uses port 443. Rule2, with priority 500, denies HTTPS traffic. Rule5, with priority changed from 2000 to 401, would allow HTTPS traffic. Note: Priority is a number between 100 and 4096. Rules are processed in priority order, with lower numbers processed before higher numbers, because lower numbers have higher priority. Once traffic matches a rule, processing stops. As a result, any rules that exist with lower priorities (higher numbers) that have the same attributes as rules with higher priorities are not processed.
upvoted 100 times
alsmk2
8 months, 2 weeks ago
Totally agree, but anyone who actually took that action rather than just create a rule with a higher priority just for 443 should be sacked on the spot. :D
upvoted 4 times
...
mlantonis
3 years, 11 months ago
Note: There are several versions of this question in the exam. The question has two possible correct answers: 1. Change the priority of Rule3 to 450. 2. For Rule5, change the Action to Allow and change the priority to 401. Other incorrect answer options you may see on the exam include the following: ✑ Modify the action of Rule1. ✑ Change the priority of Rule6 to 100. ✑ For Rule4, change the protocol from UDP to Any. Reference: https://docs.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview
upvoted 45 times
YooOY
3 years, 7 months ago
Why it works with destination set to Virtualnetwork not the PublicIP ?
upvoted 2 times
aner
2 years, 5 months ago
It works because Source (users on the Internet) is set to Any. The destination (web server) is ok to be VirtualNetwork because the web server's VM is a part of Virtual network.
upvoted 2 times
...
...
...
...
Moyuihftg
Highly Voted 3 years, 12 months ago
Answer C is correct Although not the best solution (opening range 50-5000, when you only whant to allow https/443)
upvoted 41 times
Sharathjogi
3 years, 3 months ago
Absolutely agree...that's what I am thinking, we are unnecessarily opening lot of ports here, instead of allowing just 443.
upvoted 5 times
ppuff
2 years, 9 months ago
microsoft testing logic lol
upvoted 4 times
...
...
...
Stunomatic
Most Recent 6 months ago
this is called worst firewall setup. I will like I am playing some trick game.
upvoted 1 times
...
[Removed]
7 months, 1 week ago
Selected Answer: C
C is correct
upvoted 1 times
...
froggothegood
7 months, 3 weeks ago
Selected Answer: C
The only option that does it is C because A- still have deny for 443 with higher priority (rule2) B- 443 is still denied by rule2 D- 501 is not high enough (rule2 again) This question confused me because option C is very dumb, you might as well allow everything.
upvoted 1 times
...
JackGelder
11 months, 2 weeks ago
Selected Answer: C
answer is C
upvoted 1 times
...
mkhlszf
1 year ago
Selected Answer: C
Option C would do, but a pasta strainer will be better at holding water than this server will be protected.
upvoted 2 times
...
tashakori
1 year, 1 month ago
C is right
upvoted 1 times
...
c5ad307
1 year, 3 months ago
Correct answer C: The stupidiest solution is also the correct answer...
upvoted 1 times
...
Arthur_zw
1 year, 3 months ago
For Rule5, change the Action to Allow and change the priority to 401, this would also expose RDP on port 3389 to public users and this does not satisfy the requirement to use the VM as web server only
upvoted 1 times
...
SgtDumitru
1 year, 5 months ago
Only C is a viable option. Option D will not work because Rule2 will take action.
upvoted 1 times
...
JD908
1 year, 10 months ago
Some of these rules seem redundant e.g Rule2 and Rule5 as they are. I guess its just to throw you off.
upvoted 2 times
...
UWSFish
1 year, 12 months ago
It does not speak well for Micosoft that their correct answer is very shitty IT.
upvoted 7 times
...
Phlogiston
2 years, 2 months ago
Yes, as many have commented, the correct answer is also a stupid answer that you would, if you were halfway competent, never implement in the real world. It is a poorly designed question that aspires to meet the goal of testing your ability to synthesis and analyze information, rather than simply regurgitate facts from memory. The best designed questions will require that you not only be able to recall facts but that you be able to use those facts to troubleshoot, resolve problems, or create solutions. However, the correct responses to the questions should not be bonkers stupid as this one is.
upvoted 7 times
...
MightyMonarch74
2 years, 2 months ago
Another terrible question with a ridiculous answer that does not reflect the real world!
upvoted 5 times
...
Mohd1899
2 years, 2 months ago
Microsoft want to tell us, this is not security exam so do not expect the best secured answer is the correct one, do n't expect the best practice has been implemented for each question this is a way to stop you for a simple question thinking about which answer you should select here.
upvoted 3 times
chikorita
2 years, 2 months ago
he works for microsoft
upvoted 2 times
...
...
lombri
2 years, 3 months ago
Selected Answer: D
No, it is not a good practice to open a range of ports from 400 to 500 for security reasons. In general, it is recommended to only open the specific ports that are required for a particular service to function, and to limit access to only the minimum set of IP addresses that need it. For example, in the scenario described, you only need to open port 443 to allow incoming HTTPS traffic to the web server. Opening a wider range of ports could expose the system to unnecessary security risks, as it increases the attack surface of the system. https://learn.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview https://learn.microsoft.com/en-us/azure/virtual-machines/windows/nsg-quickstart-portal https://learn.microsoft.com/en-us/azure/virtual-network/manage-network-security-group?tabs=network-security-group-portal
upvoted 2 times
Mohd1899
2 years, 3 months ago
I would agree with you if the priority for answer D is set to 499 or below in fact 501 priority eliminate this option completely because of Rule2 so the answer is C
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago