exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 13 question 1 discussion

Actual exam question from Microsoft's AZ-700
Question #: 1
Topic #: 13
[All AZ-700 Questions]

HOTSPOT -
You create NSG10 and NSG11 to meet the network security requirements.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
NSG10 which is attached to VM1's subnet blocks RDP (port TCP 3389) to 'Any' which means the port is blocked to all destinations.

Box 2: Yes -
NSG10 blocks ICMP from VNet4 (source 10.10.0.0/16) but it is not blocked from VM2's subnet (VNet1/Subnet2).

Box 3: No -
NSG11 blocks RDP (port TCP 3389) destined for 'VirtualNetwork'. VirtualNetwork is a service tag and means the address space of the virtual network (VNet1) which in this case is 10.1.0.0/16. Therefore, RDP traffic from subnet2 to anywhere else in VNet1 is blocked.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pinpin06
Highly Voted 2 years, 6 months ago
I thin the response should be YES, YES, NO 1) VM1 can establish a RDP session to VM as the filtering is set to inbound even if the rule would have matched ( it would have required outbound) 2) as stated already, this is for vnet4, so no problem, the traffic will be granted 3) the traffic will be dropped by NSG11 set as abound and from the subnet 10.1.0.0/16 to the vnet, so it matches and is dropped.
upvoted 55 times
asdasd123123iu
1 year, 2 months ago
3 - outbound means from inside of subnet to outside so in my opinion NSG allows RDP connection. If rule would be associated with inbound direction then traffic should be blocked. So, correct should be YYY
upvoted 2 times
ITrob523
3 weeks, 5 days ago
Its bound to the subnet. So it would be denied.
upvoted 1 times
...
...
Prutser2
2 years ago
agreed
upvoted 1 times
...
jeffangel28
2 years, 2 months ago
You are right!
upvoted 5 times
...
pijp
1 year, 2 months ago
Tested and you are right!
upvoted 2 times
...
...
Bon_
Highly Voted 2 years, 2 months ago
Yes, Yes, No is correct. Make sure you double-check each of the NSG rules, so it's clear! 1. From VM1 to inbound RDP VM2, there are no NSGs blocking this. There is only a custom inbound NSG for VM1, and a custom outbound NSG for VM2-- neither of which will block our connection 2. VM2 outbound NSG has no rules blocking ping (ICMP). Next review the inbound NSG for VM1. There is an priority rule 1000 -- inbound ICMP deny, but the source is pointing to VNET4 (tricky!) 3. Blocked. VM2 NSG has an outbound deny for 3389 RDP.
upvoted 18 times
...
LieJ0n
Most Recent 6 months, 2 weeks ago
Y N Y 1: Yes, the RDP block is set to inbound on subnet 1, so from vm1 (outbound) to VM 2 works 2: Yes: subnet 1 has ICMP blocked from virtualnetwork as tag destination, but the source is the subnet-4 range. so VM2 (subnet 2) can still perform RDP 3: Yes. the source IP range of the NSG does not match subnet2, this renders the custom rule useless
upvoted 1 times
...
jakubklapka
1 year, 1 month ago
In exam Sep, 2023
upvoted 2 times
...
Apptech
1 year, 7 months ago
Some basics: 1. NSG on NIC always takes precedence over NSG on Subnet. 2. Default setting for NSG is DenyAllInbound. There is one rule for all NSG linked to NIC which says RDP from Internet is allowed, which indicates that default setting for Inbound is active. What does ist mean? It means that VM1 cannot establish RDP to VM2 which NSG2 only allows RDP from Internet. Q1: No For outbound traffic default setting is Allow All. NSG10 (VNET1/Subnet2) denies ICMP only to Vnet4. Q2: YES NSG 11 on Vnet1/Subnet2 does not allow outbound for Virtual Network Also Default for NSG of Vm3 (NIC) is DenyAllInbound. Q3: NO So, in my opinion NYN is correct. https://learn.microsoft.com/en-us/azure/virtual-network/network-security-group-how-it-works
upvoted 6 times
mabalon
1 year, 2 months ago
Carefull with the point 2. yesm you have the DenyAllinbound, but also have AllowVNetInBound with better priority. with the default rules All inbound traffic from the vnet is allowed.
upvoted 2 times
...
...
JennyHuang36
1 year, 8 months ago
In exam Feb 2023
upvoted 2 times
...
TJ001
1 year, 9 months ago
yes yes no
upvoted 3 times
TJ001
1 year, 9 months ago
same vnet so route is present ...only check NSG rules....
upvoted 2 times
...
...
Mahakal_123
1 year, 10 months ago
Answer is correct, it will be NYN. No - Traffic will be dropped by NSG10. Subnet NSG will take precedence over VM interface NSG. Yes - ICMP is allowed. No - Traffic will be be dropped by NSG11.
upvoted 1 times
...
wetraining123
1 year, 11 months ago
check these two NSGS table Create an NSG named NSG10 that will be associated to Vnet1/Subnet1 and will have the custom inbound security rules shown in the following table. Create an NSG named NSG11 that will be associated to Vnet1/Subnet2 and will have the custom outbound security rules shown in the following table. so the answer is NNN
upvoted 1 times
...
wetraining123
1 year, 11 months ago
its NNN , AS THE custom nsg denies any communication from 10.1.0.0/16 which is the address space of vnet1 , and vm1 and vm2 uses that address space
upvoted 1 times
...
Gronow
2 years ago
What about the NSG's connected to the NIC's? There is only 1 rule (inbound), which is to allow RDP from Internet. Won't these block any VM/subnet RDP connections allowed via the subnet NSG? 'The NSGs are associated to the network interfaces on the virtual machines. Each NSG has one custom security rule that allows RDP connections from the internet'
upvoted 1 times
...
azeem0077
2 years, 2 months ago
Yes, Yes, No
upvoted 1 times
...
kinder2
2 years, 4 months ago
Y,Y,N.
upvoted 3 times
...
Whatsamattr81
2 years, 5 months ago
NSG10 is an inbound rule attached to subnet 1... It doesn't prevent an outbound RDP to subnet 2. Its Yes, Yes, No
upvoted 6 times
...
Kay04
2 years, 6 months ago
I believe yes yes no, no outbound filter on subnet 1.
upvoted 3 times
...
petermogaka91
2 years, 6 months ago
I think YYN for the answers
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago